RHEL 2.1 : wget (RHSA-2003:372)

high Nessus Plugin ID 12436

Synopsis

The remote Red Hat host is missing a security update.

Description

Updated wget packages that correct a buffer overrun are now available.

GNU Wget is a file-retrieval utility that uses the HTTP and FTP protocols.

A buffer overflow in the url_filename function for wget 1.8.1 allows attackers to cause a segmentation fault via a long URL. Red Hat does not believe that this issue is exploitable to allow an attacker to be able to run arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2002-1565 to this issue.

Users of wget should install the erratum package, which contains a backported security patch and is not vulnerable to this issue.

Solution

Update the affected wget package.

See Also

https://access.redhat.com/security/cve/cve-2002-1565

https://access.redhat.com/errata/RHSA-2003:372

Plugin Details

Severity: High

ID: 12436

File Name: redhat-RHSA-2003-372.nasl

Version: 1.27

Type: local

Agent: unix

Published: 7/6/2004

Updated: 1/14/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:wget, cpe:/o:redhat:enterprise_linux:2.1

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 12/10/2003

Vulnerability Publication Date: 6/16/2003

Reference Information

CVE: CVE-2002-1565

RHSA: 2003:372