Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

FreeBSD Ports: wget, wget-devel

Information

Severity

Severity

Medium

Family

Family

FreeBSD Local Security Checks

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

15 years ago

Modified

Modified

7 years ago

Summary

The remote host is missing an update to the system as announced in the referenced advisory.

Insight

Insight

The following packages are affected: wget wget-devel wgetpro wget+ipv6 CVE-2004-1487 wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a '..' that resolves to the IP address of the malicious server, which bypasses wget's filtering for '..' sequences. CVE-2004-1488 wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.

Solution

Solution

Update your system with the appropriate patches or software upgrades. http://bugs.debian.org/261755 http://marc.theaimsgroup.com/?l=bugtraq&m=110269474112384 http://www.vuxml.org/freebsd/06f142ff-4df3-11d9-a9e7-0001020eed82.html

Common Vulnerabilities and Exposures (CVE)