[Tails-dev] SSD Advisory – Wget Arbitrary Commands Execution

Supprimer ce message

Répondre à ce message
Auteur: Anonymous Remailer (austria)
Date:  
À: tails-dev
Nouveaux-sujets: Re: [Tails-dev] SSD Advisory – Wget Arbitrary Commands Execution
Sujet: [Tails-dev] SSD Advisory – Wget Arbitrary Commands Execution

"Vulnerability Description
A vulnerability in the way wget handles redirects allows attackers that are able to hijack a connection initiated by wget or compromise a server from which wget is downloading files from, would allow them to cause the user running wget to execute arbitrary commands. The commands are executed with the privileges with which wget is running. This could prove to be quite severe when wget is launched as ‘root’.

Vulnerable Version

Wget version 1.17 and prior"

More delish meaty bits:
https://blogs.securiteam.com/index.php/archives/2701