Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0244
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0244)
Resumen:The remote host is missing an update for the 'wget' package(s) announced via the MGASA-2018-0244 advisory.
Descripción:Summary:
The remote host is missing an update for the 'wget' package(s) announced via the MGASA-2018-0244 advisory.

Vulnerability Insight:
Harry Sintonen discovered that wget does not properly handle '\r\n' from
continuation lines while parsing the Set-Cookie HTTP header. A malicious
web server could use this flaw to inject arbitrary cookies to the cookie
jar file, adding new or replacing existing cookie values (CVE-2018-0494).

The Mageia 6 package has been updated to version 1.19.5, which fixes this
issue as well as other possible security issues found by fuzzing. The
Mageia 5 package has been patched to fix CVE-2018-0494.

Affected Software/OS:
'wget' package(s) on Mageia 5, Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2018-0494
BugTraq ID: 104129
http://www.securityfocus.com/bid/104129
Debian Security Information: DSA-4195 (Google Search)
https://www.debian.org/security/2018/dsa-4195
https://www.exploit-db.com/exploits/44601/
https://security.gentoo.org/glsa/201806-01
https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cd
https://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.html
https://savannah.gnu.org/bugs/?53763
https://sintonen.fi/advisories/gnu-wget-cookie-injection.txt
https://lists.debian.org/debian-lts-announce/2018/05/msg00006.html
RedHat Security Advisories: RHSA-2018:3052
https://access.redhat.com/errata/RHSA-2018:3052
http://www.securitytracker.com/id/1040838
https://usn.ubuntu.com/3643-1/
https://usn.ubuntu.com/3643-2/
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.