Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55788
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2005:204 (wget)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to wget
announced via advisory MDKSA-2005:204.

Hugo Vazquez Carames discovered a race condition when writing output
files in wget. After wget determined the output file name, but before
the file was actually opened, a local attacker with write permissions
to the download directory could create a symbolic link with the name
of the output file. This could be exploited to overwrite arbitrary
files with the permissions of the user invoking wget. The time window
of opportunity for the attacker is determined solely by the delay of
the first received data packet.

The updated packages have been patched to correct this issue.

Affected: 10.1, 10.2, Corporate 3.0, Multi Network Firewall 2.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2005:204

Risk factor : Medium

CVSS Score:
2.6

Cross-Ref: BugTraq ID: 10361
Common Vulnerability Exposure (CVE) ID: CVE-2004-2014
http://www.securityfocus.com/bid/10361
Bugtraq: 20040516 Wget race condition vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=108481268725276&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2005:204
http://marc.info/?l=wget&m=108483270227139&w=2
http://marc.info/?l=wget&m=108482747906833&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9830
http://www.redhat.com/support/errata/RHSA-2005-771.html
http://secunia.com/advisories/17399
https://usn.ubuntu.com/145-1/
XForce ISS Database: wget-lock-race-condition(16167)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16167
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.