RHEL 7 : wget (RHSA-2016:2587)
Medium Nessus Plugin ID 94550
SynopsisThe remote Red Hat host is missing one or more security updates.
DescriptionAn update for wget is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
The wget packages provide the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols.
Security Fix(es) :
* It was found that wget used a file name provided by the server for the downloaded file when following an HTTP redirect to a FTP server resource. This could cause wget to create a file with a different name than expected, possibly allowing the server to execute arbitrary code on the client. (CVE-2016-4971)
Red Hat would like to thank GNU wget project for reporting this issue.
Upstream acknowledges Dawid Golunski as the original reporter.
Additional Changes :
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.
SolutionUpdate the affected wget and / or wget-debuginfo packages.