Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://bugs.debian.org/261755
http://marc.theaimsgroup.com/?l=bugtraq&m=110269474112384 http://www.vuxml.org/freebsd/06f142ff-4df3-11d9-a9e7-0001020eed82.html
Insight
The following packages are affected:
wget
wget-devel
wgetpro
wget+ipv6
CVE-2004-1487
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a '..' that resolves to the IP address of the malicious server, which bypasses wget's filtering for '..' sequences.
CVE-2004-1488
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.
Severity
Classification
-
CVE CVE-2004-1487, CVE-2004-1488 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
Related Vulnerabilities