Oval Definition:oval:com.redhat.rhsa:def:20141764
Revision Date:2014-10-30Version:638
Title:RHSA-2014:1764: wget security update (Moderate)
Description:The wget package provides the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols.

  • A flaw was found in the way Wget handled symbolic links. A malicious FTP server could allow Wget running in the mirror mode (using the '-m' command line option) to write an arbitrary file to a location writable to by the user running Wget, possibly leading to code execution. (CVE-2014-4877)

    Note: This update changes the default value of the --retr-symlinks option. The file symbolic links are now traversed by default and pointed-to files are retrieved rather than creating a symbolic link locally.

    Red Hat would like to thank the GNU Wget project for reporting this issue. Upstream acknowledges HD Moore of Rapid7, Inc as the original reporter.

    All users of wget are advised to upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-4877
    RHSA-2014:1764
    RHSA-2014:1764-00
    RHSA-2014:1764-02
    Platform(s):Red Hat Enterprise Linux 6
    Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND wget is earlier than 0:1.14-10.el7_0.1
  • AND wget is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND wget is earlier than 0:1.12-5.el6_6.1
  • AND wget is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • wget is earlier than 0:1.14-10.el7_0.1
  • AND wget is signed with Red Hat redhatrelease2 key
  • AND
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • OR Package Information
  • wget is earlier than 0:1.12-5.el6_6.1
  • AND wget is signed with Red Hat redhatrelease2 key
  • AND
  • Red Hat Enterprise Linux 6 Client is installed
  • OR Red Hat Enterprise Linux 6 Server is installed
  • OR Red Hat Enterprise Linux 6 Workstation is installed
  • OR Red Hat Enterprise Linux 6 ComputeNode is installed
  • BACK