Ubuntu 982-1: Wget vulnerability
Summary
Update Instructions
References
Package Information
==========================================================Ubuntu Security Notice USN-982-1 September 02, 2010 wget vulnerability CVE-2010-2252 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 9.04 Ubuntu 9.10 Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: wget 1.10.2-1ubuntu1.2 Ubuntu 8.04 LTS: wget 1.10.2-3ubuntu1.2 Ubuntu 9.04: wget 1.11.4-2ubuntu1.2 Ubuntu 9.10: wget 1.11.4-2ubuntu2.1 Ubuntu 10.04 LTS: wget 1.12-1.1ubuntu2.1 In general, a standard system update will make all the necessary changes. ATTENTION: This update changes previous behaviour by ignoring the filename supplied by the server during redirects. To re-enable previous behaviour, use the new --trust-server-names option. Details follow: It was discovered that Wget would use filenames provided by the server when following 3xx redirects. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary code. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 15892 cf77f701f7a4e993600edad00efcb22b Size/MD5: 636 d97a4c2c68465eace270b7e066218d20 Size/MD5: 1213056 795fefbb7099f93e2d346b026785c4b8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 622210 14e3fe0952664e287ff0f3ad1efdb947 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 610956 545ece29bffbd451068ade4aec1f7b3d powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 616878 7f9cd84636c7fcd64ce570a1a213d027 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 614284 a8232e9723c4378c4366035c97a3b2b4 Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 170652 808bbaa03c0ddbc392de9e156e44d70f Size/MD5: 725 7789909434c005ca0a74ddf4987405ca Size/MD5: 1213056 795fefbb7099f93e2d346b026785c4b8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 246336 483cb327b9925c4c4ad660610432eda3 Size/MD5: 113960 df7a72385e0989cbeb9120dc844644d7 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 238342 3b9335d320bceae4b9555d9b74c4040f Size/MD5: 106554 6d8a1ac0eed86310027f5e6145bf6c1f lpia architecture (Low Power Intel Architecture): Size/MD5: 237898 f587451d75d63a81785d7e6629a8c17f Size/MD5: 106532 6b11a315636f4912cd549b6c168fd3d9 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 253578 0b2f81b9117f86a186c16a02c6f495ed Size/MD5: 121610 65e64e7f815d0e057d5cbba011aee99a sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 239594 5fecc36c30a89b2a52b41d83370728b3 Size/MD5: 107364 efb59b7498fe2310245fbe0acd702dda Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 20472 2fe3cb90188edccb119d695b252c52ec Size/MD5: 1163 46bf0822cb7b2f7e1780e6d55518c5b5 Size/MD5: 1475149 69e8a7296c0e12c53bd9ffd786462e87 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 250278 e70c5a94f4784802170d203cfe048dc5 Size/MD5: 119430 2f4865e3621b3b5e683c7eea8d50bd72 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 242184 7ec6ab101f8b54fcd3a4eb4973e8c5ba Size/MD5: 112306 faba926b7c0281a9cba9609ffb116ab2 lpia architecture (Low Power Intel Architecture): Size/MD5: 241654 ebb730a6648fb51800170c6aaa09c26b Size/MD5: 111472 3bfbbc78255499d97fb0a7417b633b52 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 257280 4de44eb570dcbcbd914a05a607eb61ec Size/MD5: 126396 53177ed5a04dfdb69d45f514945aacb6 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 244156 bf3de555a18c3bb78b10e866945571fa Size/MD5: 113940 8375c1bde59077f34bf11553a5d3a682 Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 20475 c2f5506a48724dbb740f2521c1de4f89 Size/MD5: 1163 361efdd9a29385b4c103204450f47836 Size/MD5: 1475149 69e8a7296c0e12c53bd9ffd786462e87 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 250552 8e8cb96704eeaa7da3645fe9c7d8be37 Size/MD5: 119858 cdb9527d2cb1aa9bacf7b6661e08a165 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 242296 faf0ddbc9f3f1f7d5f1bb9bca6b80482 Size/MD5: 112514 b5a04f9370035619da4420b48790974c lpia architecture (Low Power Intel Architecture): Size/MD5: 242284 18c9fe76cbff7ad8c0f65416bd56a6ae Size/MD5: 111900 ddf58cb0f68cdcd55861f5b6f0719447 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 256280 babdfe39a32131fcfbdac46025b14fa9 Size/MD5: 125580 2a28c607eb2cc0c33a42ecceb9548be0 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 244904 e01fe75257425084b8741c59c95c8f22 Size/MD5: 115100 d30c70836434f6dea3cdb47acd0d4b0b Updated packages for Ubuntu 10.04: Source archives: Size/MD5: 40454 0d331ab6957f872485bbe36a52bcbfd2 Size/MD5: 1160 d4178e19150826c6c1101b16a67cfc67 Size/MD5: 2464747 141461b9c04e454dc8933c9d1f2abf83 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 154596 a306db8ee52b32ab4f862ad4784c9390 Size/MD5: 296866 fca95e99bc1fbf4d33735d5774d082f5 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 145538 6080b539c186fe8a6bb57bbecf108f95 Size/MD5: 289402 78a00423731f5b937087fda628fc251c powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 158994 cce4fe5f77fb58eb4cd30ed7cccac07b Size/MD5: 301042 aa09b5eeafedd0d5439113bdc47a1bbc sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 149686 2505903c358ce719672a01f90312dc8b Size/MD5: 292668 563284a73f1506acdff6d0540d5745ed