FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

wget -- Heap overflow in HTTP protocol handling

Affected packages
wget < 1.19.2


VuXML ID d77ceb8c-bb13-11e7-8357-3065ec6f3643
Discovery 2017-10-20
Entry 2017-10-27

Antti Levomäki, Christian Jalio, Joonas Pihlaja:

Wget contains two vulnerabilities, a stack overflow and a heap overflow, in the handling of HTTP chunked encoding. By convincing a user to download a specific link over HTTP, an attacker may be able to execute arbitrary code with the privileges of the user.


CVE Name CVE-2017-13090