Bugzilla – Bug 902709
VUL-0: CVE-2014-4877: wget: FTP symlink arbitrary filesystem access
Last modified: 2020-06-17 02:13:06 UTC
rh#1139181 References: https://bugzilla.redhat.com/show_bug.cgi?id=1139181 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4877 http://seclists.org/oss-sec/2014/q4/453 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4877 http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
bugbot adjusting priority
proposed patch http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2014-11-06. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/59546
network:utilities 1.16 fixed, pending SR to openSUSE:Factory openSUSE 13.2: 1.15 affected openSUSE 13.1: 1.14 affected openSUSE 12.3: 1.13.4 affected
Maintenance request to update openSUSE 12.3+13.1+13.2 to wget 1.16: https://build.opensuse.org/request/show/259043 Please review if that is okay. To openSUSE:Factory: https://build.opensuse.org/request/show/258921
Reinhard? Please submit.
Due to high remote CVSS scoring and customer awareness even though this is not a problematic issue we have decided to also release LTSS updates for the exsisting LTSS codestreams. (Nothing for you to do Reinhard, same source is used for LTSS as submitted.)
SUSE-SU-2014:1366-1: An update that solves one vulnerability and has two fixes is now available. Category: security (important) Bug References: 885069,901276,902709 CVE References: CVE-2014-4877 Sources used: SUSE Linux Enterprise Server 11 SP3 for VMware (src): wget-1.11.4-1.19.1 SUSE Linux Enterprise Server 11 SP3 (src): wget-1.11.4-1.19.1 SUSE Linux Enterprise Desktop 11 SP3 (src): wget-1.11.4-1.19.1
SUSE-SU-2014:1408-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 902709 CVE References: CVE-2014-4877 Sources used: SUSE Linux Enterprise Server 10 SP4 LTSS (src): wget-1.10.2-15.14.5
SUSE-SU-2014:1366-2: An update that solves one vulnerability and has two fixes is now available. Category: security (important) Bug References: 885069,901276,902709 CVE References: CVE-2014-4877 Sources used: SUSE Linux Enterprise Server 11 SP2 LTSS (src): wget-1.11.4-1.19.1 SUSE Linux Enterprise Server 11 SP1 LTSS (src): wget-1.11.4-1.19.1
SUSE-SU-2014:1464-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 902709 CVE References: CVE-2014-4877 Sources used: SUSE Linux Enterprise Server 12 (src): wget-1.14-7.1 SUSE Linux Enterprise Desktop 12 (src): wget-1.14-7.1
all done now I think.