Heap-based buffer overflow in wget - CVE-2017-13089
Published: October 26, 2017 / Updated: October 31, 2017
Vulnerability details
The vulnerability exists due to heap-based buffer overflow in the skip_short_body() function in 'src/http.c' when processing HTTP chunk size values. A remote attacker can send specially crafted HTTP data, trigger memory corruption and execute arbitrary code with privileges of the current user.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Slackware Linux
Fedora
wget (Alpine package)
wget
How to mitigate CVE-2017-13089
wget - addressed in versions 1.19.2-1.fc25, 1.19.2-1.fc26, 1.19.2-1.fc27
External References
Related Security Bulletins
- Remote code execution in wget
- Red Hat update for wget
- Slackware Linux update for wget
- Debian update for wget
- Arch Linux update for wget
- Amazon Linux AMI update for wget
- Gentoo update for GNU Wget
- Ubuntu update for Wget
- Ubuntu update for Wget
- OpenSUSE Linux update for wget
- SUSE Linux update for wget
- SUSE Linux update for wget
- Heap-based buffer overflow in wget (Alpine package)
- Fedora 27 update for wget
- Fedora 25 update for wget
- Fedora 26 update for wget