FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

wget -- Stack overflow in HTTP protocol handling

Affected packages
wget < 1.19.2

Details

VuXML ID 09849e71-bb12-11e7-8357-3065ec6f3643
Discovery 2017-10-20
Entry 2017-10-27

Antti Levomäki, Christian Jalio, Joonas Pihlaja:

Wget contains two vulnerabilities, a stack overflow and a heap overflow, in the handling of HTTP chunked encoding. By convincing a user to download a specific link over HTTP, an attacker may be able to execute arbitrary code with the privileges of the user.

References

CVE Name CVE-2017-13089
URL http://git.savannah.gnu.org/cgit/wget.git/commit/?id=d892291fb8ace4c3b734ea5125770989c215df3f