Bug 995964 (CVE-2016-7098) - VUL-1: CVE-2016-7098: wget: files rejected by access list are kept on the disk for the duration of HTTP connection
Summary: VUL-1: CVE-2016-7098: wget: files rejected by access list are kept on the dis...
Status: RESOLVED FIXED
Alias: CVE-2016-7098
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/172199/
Whiteboard: CVSSv2:RedHat:CVE-2016-7098:2.6:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-29 08:20 UTC by Alexander Bergmann
Modified: 2018-10-07 22:40 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2016-08-29 08:20:14 UTC
rh#1328137

A possible vulnerability was found in wget. The vulnerability surfaces when wget is used to download a single file with recursive option (-r / -m) and an access list ( -A ), wget only applies the list at the end of the download process.

Although the file get successfully deleted in the end, this creates a race condition situation as an attacker who has control over the URL, could slow down the download process so that he had a chance to make use of the malicious file before it gets deleted.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1328137
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-7098
http://seclists.org/oss-sec/2016/q3/385
http://lists.gnu.org/archive/html/bug-wget/2016-08/msg00134.html
Comment 1 Swamp Workflow Management 2016-08-29 22:00:14 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2016-09-01 12:33:27 UTC
if possible, submit this as update, so we can fold it in the running wget ones
Comment 3 Bernhard Wiedemann 2016-09-02 12:00:21 UTC
This is an autogenerated message for OBS integration:
This bug (995964) was mentioned in
https://build.opensuse.org/request/show/424440 13.2 / wget
Comment 6 Swamp Workflow Management 2016-09-10 13:09:02 UTC
openSUSE-SU-2016:2284-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 995964
CVE References: CVE-2016-7098
Sources used:
openSUSE 13.2 (src):    wget-1.16-4.10.1
Comment 7 Josef Möllers 2016-09-20 10:19:27 UTC
Resolved by applying upstream patch.
Comment 8 Marcus Meissner 2016-09-20 15:42:35 UTC
reopenb
Comment 9 Marcus Meissner 2016-09-20 15:48:14 UTC
i see you resubmitted, thanks. 

reassign to security team for tracking and later closing.
Comment 10 Swamp Workflow Management 2016-09-23 16:11:26 UTC
SUSE-SU-2016:2358-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 958342,984060,995964
CVE References: CVE-2016-4971,CVE-2016-7098
Sources used:
SUSE OpenStack Cloud 5 (src):    wget-1.11.4-1.32.1
SUSE Manager Proxy 2.1 (src):    wget-1.11.4-1.32.1
SUSE Manager 2.1 (src):    wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11-SP4 (src):    wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11-SP3-LTSS (src):    wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11-SECURITY (src):    wget-openssl1-1.11.4-1.32.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    wget-1.11.4-1.32.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    wget-1.11.4-1.32.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    wget-1.11.4-1.32.1
Comment 11 Swamp Workflow Management 2016-12-23 20:07:48 UTC
SUSE-SU-2016:3268-1: An update that solves one vulnerability and has two fixes is now available.

Category: security (moderate)
Bug References: 1005091,1012677,995964
CVE References: CVE-2016-7098
Sources used:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    wget-1.14-17.1
SUSE Linux Enterprise Server 12-SP2 (src):    wget-1.14-17.1
SUSE Linux Enterprise Server 12-SP1 (src):    wget-1.14-17.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    wget-1.14-17.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    wget-1.14-17.1
Comment 12 Swamp Workflow Management 2017-01-03 19:07:52 UTC
openSUSE-SU-2017:0015-1: An update that solves one vulnerability and has two fixes is now available.

Category: security (moderate)
Bug References: 1005091,1012677,995964
CVE References: CVE-2016-7098
Sources used:
openSUSE Leap 42.2 (src):    wget-1.14-6.1
openSUSE Leap 42.1 (src):    wget-1.14-8.1
Comment 13 Marcus Meissner 2017-10-25 13:05:09 UTC
released