Heap-based buffer overflow in wget - CVE-2017-13090
Published: October 27, 2017 / Updated: October 31, 2017
Vulnerability details
The vulnerability exists due to heap-based buffer overflow in the fd_read_body() function in 'src/retr.c'' when processing HTTP chunk size values. A remote attacker can send specially crafted HTTP data, trigger memory corruption and execute arbitrary code with privileges of the current user.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for x86_64
SUSE Linux
Slackware Linux
Ubuntu
Fedora
wget (Alpine package)
wget
How to mitigate CVE-2017-13090
wget - addressed in versions 1.19.2-1.fc25, 1.19.2-1.fc26, 1.19.2-1.fc27
External References
Related Security Bulletins
- Remote code execution in wget
- Red Hat update for wget
- Slackware Linux update for wget
- Debian update for wget
- Arch Linux update for wget
- Amazon Linux AMI update for wget
- Gentoo update for GNU Wget
- Ubuntu update for Wget
- OpenSUSE Linux update for wget
- SUSE Linux update for wget
- SUSE Linux update for wget
- Heap-based buffer overflow in wget (Alpine package)
- Fedora 27 update for wget
- Fedora 25 update for wget
- Fedora 26 update for wget