FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

wget -- Heap overflow in HTTP protocol handling

Affected packages
wget < 1.19.2

Details

VuXML ID d77ceb8c-bb13-11e7-8357-3065ec6f3643
Discovery 2017-10-20
Entry 2017-10-27

Antti Levomäki, Christian Jalio, Joonas Pihlaja:

Wget contains two vulnerabilities, a stack overflow and a heap overflow, in the handling of HTTP chunked encoding. By convincing a user to download a specific link over HTTP, an attacker may be able to execute arbitrary code with the privileges of the user.

References

CVE Name CVE-2017-13090
URL http://git.savannah.gnu.org/cgit/wget.git/commit/?id=ba6b44f6745b14dce414761a8e4b35d31b176bba