wget-1.12-1.11.AXS4

エラータID: AXSA:2014-010:01

Release date: 
Wednesday, March 12, 2014 - 19:06
Subject: 
wget-1.12-1.11.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

GNU Wget is a file retrieval utility which can use either the HTTP or FTP protocols. Wget features include the ability to work in the background while you are logged out, recursive retrieval of directories, file name wildcard matching, remote file timestamp storage and comparison, use of Rest with FTP servers and Range with HTTP servers to retrieve files over slow or unstable connections, support for Proxy servers, and configurability.

Security issues fixed with this release:

• CVE-2010-2252
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

Fixed bugs:

• Previously, wget did not support HTTPS SSL certificates with alternative names specified in the certificate as valid and would fail with a certificate error. This has been fixed.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. wget-1.12-1.11.AXS4.src.rpm
    MD5: 41cc5a9fb78df7356690e06504c35013
    SHA-256: 974a20dccb49de76d20089449864bca4460087ac0c97e8e127ae6aae825a0b19
    Size: 1.56 MB

Asianux Server 4 for x86
  1. wget-1.12-1.11.AXS4.i686.rpm
    MD5: 2e67b72860e36ac373ff5c7d783e38ae
    SHA-256: 2002f9ce4ca540c1da5f765ff34d667a49ef39356261a6a3ab1616b633b17622
    Size: 485.60 kB

Asianux Server 4 for x86_64
  1. wget-1.12-1.11.AXS4.x86_64.rpm
    MD5: f337db17f79dcf5195218631d4b7e27d
    SHA-256: d464123a341fc9ed841c786372c9257dba9464937404ff33dc2ee142dc87f99a
    Size: 486.39 kB