Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.67997
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: wget, wget-devel
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

wget
wget-devel

CVE-2010-2252
GNU Wget 1.12 and earlier uses a server-provided filename instead of
the original URL to determine the destination filename of a download,
which allows remote servers to create or overwrite arbitrary files via
a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx
redirect to a URL with a crafted filename, and possibly execute
arbitrary code as a consequence of writing to a dotfile in a home
directory.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-2252
BugTraq ID: 65722
http://www.securityfocus.com/bid/65722
http://www.ocert.org/advisories/ocert-2010-001.html
http://lists.gnu.org/archive/html/bug-wget/2010-05/msg00031.html
http://lists.gnu.org/archive/html/bug-wget/2010-05/msg00033.html
http://lists.gnu.org/archive/html/bug-wget/2010-05/msg00023.html
http://lists.gnu.org/archive/html/bug-wget/2010-05/msg00032.html
http://lists.gnu.org/archive/html/bug-wget/2010-05/msg00034.html
http://marc.info/?l=oss-security&m=127412569216380&w=2
http://marc.info/?l=oss-security&m=127411372529485&w=2
http://marc.info/?l=oss-security&m=127416905831994&w=2
http://marc.info/?l=oss-security&m=127422615924593&w=2
http://marc.info/?l=oss-security&m=127427572721591&w=2
http://marc.info/?l=oss-security&m=127432968701342&w=2
http://marc.info/?l=oss-security&m=127441275821210&w=2
http://marc.info/?l=oss-security&m=127611288927500&w=2
RedHat Security Advisories: RHSA-2014:0151
http://rhn.redhat.com/errata/RHSA-2014-0151.html
CopyrightCopyright (C) 2010 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.