This script is Copyright (C) 2010-2013 Tenable Network Security, Inc.
The remote FreeBSD host is missing one or more security-related
GNU Wget version 1.12 and earlier uses a server-provided filename
instead of the original URL to determine the destination filename of a
download, which allows remote servers to create or overwrite arbitrary
files via a 3xx redirect to a URL with a .wgetrc filename followed by
a 3xx redirect to a URL with a crafted filename, and possibly execute
arbitrary code as a consequence of writing to a dotfile in a home
See also :
Update the affected packages.
Risk factor :
Medium / CVSS Base Score : 6.8