[Tails-dev] SSD Advisory – Wget Arbitrary Commands Execution

Delete this message

Reply to this message
Autor: Anonymous Remailer (austria)
Data:  
Para: tails-dev
Novos Tópicos: Re: [Tails-dev] SSD Advisory – Wget Arbitrary Commands Execution
Assunto: [Tails-dev] SSD Advisory – Wget Arbitrary Commands Execution

"Vulnerability Description
A vulnerability in the way wget handles redirects allows attackers that are able to hijack a connection initiated by wget or compromise a server from which wget is downloading files from, would allow them to cause the user running wget to execute arbitrary commands. The commands are executed with the privileges with which wget is running. This could prove to be quite severe when wget is launched as ‘root’.

Vulnerable Version

Wget version 1.17 and prior"

More delish meaty bits:
https://blogs.securiteam.com/index.php/archives/2701