Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2016.0323
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2016-0323)
Resumen:The remote host is missing an update for the 'wget' package(s) announced via the MGASA-2016-0323 advisory.
Descripción:Summary:
The remote host is missing an update for the 'wget' package(s) announced via the MGASA-2016-0323 advisory.

Vulnerability Insight:
GNU wget before 1.18 allows remote servers to write to arbitrary files by
redirecting a request from HTTP to a crafted FTP resource (CVE-2016-4971).

Fixed a potential race condition by creating files with .tmp ext and
making them accessible to the current user only (CVE-2016-7098).

Affected Software/OS:
'wget' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-4971
1036133
http://www.securitytracker.com/id/1036133
40064
https://www.exploit-db.com/exploits/40064/
91530
http://www.securityfocus.com/bid/91530
GLSA-201610-11
https://security.gentoo.org/glsa/201610-11
RHSA-2016:2587
http://rhn.redhat.com/errata/RHSA-2016-2587.html
USN-3012-1
http://www.ubuntu.com/usn/USN-3012-1
[info-gnu] 20160609 GNU wget 1.18 released
http://lists.gnu.org/archive/html/info-gnu/2016-06/msg00004.html
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=e996e322ffd42aaa051602da182d03178d0f13e1
http://packetstormsecurity.com/files/162395/GNU-wget-Arbitrary-File-Upload-Code-Execution.html
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
https://bugzilla.redhat.com/show_bug.cgi?id=1343666
https://security.paloaltonetworks.com/CVE-2016-4971
openSUSE-SU-2016:2027
http://lists.opensuse.org/opensuse-updates/2016-08/msg00043.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-7098
40824
https://www.exploit-db.com/exploits/40824/
93157
http://www.securityfocus.com/bid/93157
[bug-wget] 20160814 Wget - acess list bypass / race condition PoC
http://lists.gnu.org/archive/html/bug-wget/2016-08/msg00083.html
[bug-wget] 20160824 Re: Wget - acess list bypass / race condition PoC
http://lists.gnu.org/archive/html/bug-wget/2016-08/msg00134.html
[debian-lts-announce] 20200129 [SECURITY] [DLA 2086-1] wget security update
https://lists.debian.org/debian-lts-announce/2020/01/msg00031.html
[oss-security] 20160827 Re: CVE Request - Gnu Wget 1.17 - Design Error Vulnerability
http://www.openwall.com/lists/oss-security/2016/08/27/2
openSUSE-SU-2016:2284
http://lists.opensuse.org/opensuse-updates/2016-09/msg00044.html
openSUSE-SU-2017:0015
http://lists.opensuse.org/opensuse-updates/2017-01/msg00007.html
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.