Re: Bug in wget: CVE-2014-4877

Thomas Biege <[email protected]>
Newsgroups gmane.linux.suse.security
Message-ID <[email protected]>
Hi,

we already started an update for SLE. We will release it as soon as
possible based on impact and relative to other running issues.

The openSUSE community is happy about every helping hand... so if you
want to learn something about packaging and the build-service, feel free.

Bye,
Thomas


On 10/30/2014 10:20 AM, Sverre Moe wrote:
> A new version of wget is out, 1.16
> 
> http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.html
> * Noteworthy changes in Wget 1.16
> ** No longer create local symbolic links by default. Closes CVE-2014-4877.
> 
> http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4877
> 
> https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access
> 
> OpenSUSE 13.1 uses wget-1.14
> Last changes: Thu May 2 17:50:50 UTC 2013
> https://build.opensuse.org/package/show/openSUSE:13.1/wget
> 
> OpenSUSE 13.2 uses wget-1.15
> Last changes: Sun Jan 19 22:02:25 UTC 2014
> https://build.opensuse.org/package/show/openSUSE:13.2/wget
> 
> When will we see a fix for wget on OpenSUSE?
> I also use some SLES and have not seen any indication that SUSE is on
> this either.
> 


-- 
Thomas Biege <[email protected]>, Team Leader MaintenanceSecurity, CSSLP
SUSE LINUX Products GmbH
GF: Jeff Hawn, Jennifer Guild, Felix Imendörffer
HRB 21284 (AG Nürnberg)
--
  Wer aufhoert besser werden zu wollen, hoert auf gut zu sein.
                            -- Marie von Ebner-Eschenbach
signature.asc (application/pgp-signature, 538 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBAgAGBQJUUlqSAAoJEJqHoVJVjr8D8LUIAJmsYF34XNLf1wXP7Lp3Ijq3
CMlX+oeH7V7JEtH4tHQ4/YKfOJ7cEfpCX7cNHqZcWWVlhF+ImFAXli+aUSaylyqD
tsVZL63/nfte4/blHG75nysN6RE73rjVsIL2OTXcnDdhoZNBMiW9Xp+I6jJbnkL0
2zofbTDrbRDEYydvXnZUH8wqkafUl4LbUI3w0pUoBSTz4KpFZ/YE1lMfaxNDhscH
2+YcDVRKtCQn5VuMsVqRpmrGeMn/Djb7a3Q8VFYf66MRwSIhkeTk0QasrtX9F78y
PoHQc+zMm5ZiZrVPvYon9zJymmkhJ/6lW5mMRwxp+tb2PUPT7vC8Unm6OVTKN0M=
=sUC7
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.