2014-10-29
ALT-BU-2014-3075-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2014-11-16
BDU:2015-09791
Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Severity: CRITICAL (9.3)
References:
Published: 2014-10-29
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2014-4877
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
Severity: CRITICAL (9.3)
References:
- http://advisories.mageia.org/MGASA-2014-0431.html
- http://advisories.mageia.org/MGASA-2014-0431.html
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0
- [bug-wget] 20141027 GNU wget 1.16 released
- [bug-wget] 20141027 GNU wget 1.16 released
- SUSE-SU-2014:1366
- SUSE-SU-2014:1366
- SUSE-SU-2014:1408
- SUSE-SU-2014:1408
- openSUSE-SU-2014:1380
- openSUSE-SU-2014:1380
- RHSA-2014:1764
- RHSA-2014:1764
- RHSA-2014:1955
- RHSA-2014:1955
- GLSA-201411-05
- GLSA-201411-05
- DSA-3062
- DSA-3062
- VU#685996
- VU#685996
- MDVSA-2015:121
- MDVSA-2015:121
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- 70751
- 70751
- USN-2393-1
- USN-2393-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1139181
- https://bugzilla.redhat.com/show_bug.cgi?id=1139181
- https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access
- https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access
- https://github.com/rapid7/metasploit-framework/pull/4088
- https://github.com/rapid7/metasploit-framework/pull/4088
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://kc.mcafee.com/corporate/index?page=content&id=SB10106
- https://kc.mcafee.com/corporate/index?page=content&id=SB10106