Mandrake Linux Security Advisory : wget (MDKSA-2002:086)

medium Nessus Plugin ID 13984

Synopsis

The remote Mandrake Linux host is missing a security update.

Description

A vulnerability in all versions of wget prior to and including 1.8.2 was discovered by Steven M. Christey. The bug permits a malicious FTP server to create or overwriet files anywhere on the local file system by sending filenames beginning with '/' or containing '/../'. This can be used to make vulnerable FTP clients write files that can later be used for attack against the client machine.

Solution

Update the affected wget package.

See Also

http://marc.info/?l=bugtraq&m=87602746719482

Plugin Details

Severity: Medium

ID: 13984

File Name: mandrake_MDKSA-2002-086.nasl

Version: 1.20

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:wget, cpe:/o:mandrakesoft:mandrake_linux:7.2, cpe:/o:mandrakesoft:mandrake_linux:8.0, cpe:/o:mandrakesoft:mandrake_linux:8.1, cpe:/o:mandrakesoft:mandrake_linux:8.2, cpe:/o:mandrakesoft:mandrake_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 12/11/2002

Reference Information

CVE: CVE-2002-1344

MDKSA: 2002:086