USN-3464-1: Wget vulnerabilities Ubuntu Security Notice USN-3464-1 26th October, 2017 wget vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Wget. Software description wget – retrieves files from the web Details Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wgetincorrectly handled certain HTTP responses. A remote attacker could usethis issue to cause Wget to crash, resulting in a denial of service, orpossibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090) Dawid Golunski discovered that Wget incorrectly handled recursive ormirroring mode. A remote attacker could possibly use this issue to bypassintended access list restrictions. (CVE-2016-7098) Orange Tsai discovered that Wget incorrectly handled CRLF sequences inHTTP headers. A remote attacker could possibly use this issue to injectarbitrary HTTP headers. (CVE-2017-6508) Update instructions The problem [ more… ]