SUSE-SU-2016:2358-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2358-1
SUSE-SU-2016:2358-1
Summary: Security update for wget
Details: This update for wget fixes the following issues: - CVE-2016-4971: A HTTP to FTP redirection file name confusion vulnerability was fixed. (bsc#984060). - CVE-2016-7098: A potential race condition was fixed by creating files with .tmp ext and making them accessible to the current user only. (bsc#995964) Bug fixed: - Wget failed with basicauth: Failed writing HTTP request: Bad file descriptor (bsc#958342)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162358-1/, https://bugzilla.suse.com/958342, https://bugzilla.suse.com/984060, https://bugzilla.suse.com/995964, https://www.suse.com/security/cve/CVE-2016-4971, https://www.suse.com/security/cve/CVE-2016-7098
Affected packages
Package
Name: wget-openssl1
Purl: pkg:rpm/suse/wget-openssl1&distro=SUSE%20Linux%20Enterprise%20Server%2011-SECURITY
Affected ranges
Type: ECOSYSTEM
Events:
