Articles / Ubuntu: New wget packages f...

Ubuntu: New wget packages fix security vulnerability

It was discovered that Wget would use filenames provided by the server when following 3xx redirects. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary code. Updated packages are available from security.ubuntu.com.

===========================================================
Ubuntu Security Notice USN-982-1         September 02, 2010
wget vulnerability
CVE-2010-2252
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
 wget                            1.10.2-1ubuntu1.2

Ubuntu 8.04 LTS:
 wget                            1.10.2-3ubuntu1.2

Ubuntu 9.04:
 wget                            1.11.4-2ubuntu1.2

Ubuntu 9.10:
 wget                            1.11.4-2ubuntu2.1

Ubuntu 10.04 LTS:
 wget                            1.12-1.1ubuntu2.1

In general, a standard system update will make all the necessary changes.

ATTENTION: This update changes previous behaviour by ignoring the filename
supplied by the server during redirects. To re-enable previous behaviour,
use the new --trust-server-names option.

Details follow:

It was discovered that Wget would use filenames provided by the server when
following 3xx redirects. If a user or automated system were tricked into
downloading a file from a malicious site, a remote attacker could create
the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary
code.


Updated packages for Ubuntu 6.06 LTS:

 Source archives:

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2.diff.gz
     Size/MD5:    15892 cf77f701f7a4e993600edad00efcb22b
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2.dsc
     Size/MD5:      636 d97a4c2c68465eace270b7e066218d20
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2.orig.tar.gz
     Size/MD5:  1213056 795fefbb7099f93e2d346b026785c4b8

 amd64 architecture (Athlon64, Opteron, EM64T Xeon):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_amd64.deb
     Size/MD5:   622210 14e3fe0952664e287ff0f3ad1efdb947

 i386 architecture (x86 compatible Intel/AMD):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_i386.deb
     Size/MD5:   610956 545ece29bffbd451068ade4aec1f7b3d

 powerpc architecture (Apple Macintosh G3/G4/G5):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_powerpc.deb
     Size/MD5:   616878 7f9cd84636c7fcd64ce570a1a213d027

 sparc architecture (Sun SPARC/UltraSPARC):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_sparc.deb
     Size/MD5:   614284 a8232e9723c4378c4366035c97a3b2b4

Updated packages for Ubuntu 8.04 LTS:

 Source archives:

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2.diff.gz
     Size/MD5:   170652 808bbaa03c0ddbc392de9e156e44d70f
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2.dsc
     Size/MD5:      725 7789909434c005ca0a74ddf4987405ca
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2.orig.tar.gz
     Size/MD5:  1213056 795fefbb7099f93e2d346b026785c4b8

 amd64 architecture (Athlon64, Opteron, EM64T Xeon):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_amd64.deb
     Size/MD5:   246336 483cb327b9925c4c4ad660610432eda3
   http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_amd64.udeb
     Size/MD5:   113960 df7a72385e0989cbeb9120dc844644d7

 i386 architecture (x86 compatible Intel/AMD):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_i386.deb
     Size/MD5:   238342 3b9335d320bceae4b9555d9b74c4040f
   http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_i386.udeb
     Size/MD5:   106554 6d8a1ac0eed86310027f5e6145bf6c1f

 lpia architecture (Low Power Intel Architecture):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_lpia.deb
     Size/MD5:   237898 f587451d75d63a81785d7e6629a8c17f
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_lpia.udeb
     Size/MD5:   106532 6b11a315636f4912cd549b6c168fd3d9

 powerpc architecture (Apple Macintosh G3/G4/G5):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_powerpc.deb
     Size/MD5:   253578 0b2f81b9117f86a186c16a02c6f495ed
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_powerpc.udeb
     Size/MD5:   121610 65e64e7f815d0e057d5cbba011aee99a

 sparc architecture (Sun SPARC/UltraSPARC):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_sparc.deb
     Size/MD5:   239594 5fecc36c30a89b2a52b41d83370728b3
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_sparc.udeb
     Size/MD5:   107364 efb59b7498fe2310245fbe0acd702dda

Updated packages for Ubuntu 9.04:

 Source archives:

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2.diff.gz
     Size/MD5:    20472 2fe3cb90188edccb119d695b252c52ec
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2.dsc
     Size/MD5:     1163 46bf0822cb7b2f7e1780e6d55518c5b5
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4.orig.tar.gz
     Size/MD5:  1475149 69e8a7296c0e12c53bd9ffd786462e87

 amd64 architecture (Athlon64, Opteron, EM64T Xeon):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_amd64.deb
     Size/MD5:   250278 e70c5a94f4784802170d203cfe048dc5
   http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_amd64.udeb
     Size/MD5:   119430 2f4865e3621b3b5e683c7eea8d50bd72

 i386 architecture (x86 compatible Intel/AMD):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_i386.deb
     Size/MD5:   242184 7ec6ab101f8b54fcd3a4eb4973e8c5ba
   http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_i386.udeb
     Size/MD5:   112306 faba926b7c0281a9cba9609ffb116ab2

 lpia architecture (Low Power Intel Architecture):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_lpia.deb
     Size/MD5:   241654 ebb730a6648fb51800170c6aaa09c26b
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_lpia.udeb
     Size/MD5:   111472 3bfbbc78255499d97fb0a7417b633b52

 powerpc architecture (Apple Macintosh G3/G4/G5):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_powerpc.deb
     Size/MD5:   257280 4de44eb570dcbcbd914a05a607eb61ec
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_powerpc.udeb
     Size/MD5:   126396 53177ed5a04dfdb69d45f514945aacb6

 sparc architecture (Sun SPARC/UltraSPARC):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_sparc.deb
     Size/MD5:   244156 bf3de555a18c3bb78b10e866945571fa
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_sparc.udeb
     Size/MD5:   113940 8375c1bde59077f34bf11553a5d3a682

Updated packages for Ubuntu 9.10:

 Source archives:

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1.diff.gz
     Size/MD5:    20475 c2f5506a48724dbb740f2521c1de4f89
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1.dsc
     Size/MD5:     1163 361efdd9a29385b4c103204450f47836
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4.orig.tar.gz
     Size/MD5:  1475149 69e8a7296c0e12c53bd9ffd786462e87

 amd64 architecture (Athlon64, Opteron, EM64T Xeon):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_amd64.deb
     Size/MD5:   250552 8e8cb96704eeaa7da3645fe9c7d8be37
   http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_amd64.udeb
     Size/MD5:   119858 cdb9527d2cb1aa9bacf7b6661e08a165

 i386 architecture (x86 compatible Intel/AMD):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_i386.deb
     Size/MD5:   242296 faf0ddbc9f3f1f7d5f1bb9bca6b80482
   http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_i386.udeb
     Size/MD5:   112514 b5a04f9370035619da4420b48790974c

 lpia architecture (Low Power Intel Architecture):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_lpia.deb
     Size/MD5:   242284 18c9fe76cbff7ad8c0f65416bd56a6ae
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_lpia.udeb
     Size/MD5:   111900 ddf58cb0f68cdcd55861f5b6f0719447

 powerpc architecture (Apple Macintosh G3/G4/G5):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_powerpc.deb
     Size/MD5:   256280 babdfe39a32131fcfbdac46025b14fa9
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_powerpc.udeb
     Size/MD5:   125580 2a28c607eb2cc0c33a42ecceb9548be0

 sparc architecture (Sun SPARC/UltraSPARC):

   http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_sparc.deb
     Size/MD5:   244904 e01fe75257425084b8741c59c95c8f22
   http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_sparc.udeb
     Size/MD5:   115100 d30c70836434f6dea3cdb47acd0d4b0b

Updated packages for Ubuntu 10.04:

 Source archives:

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1.diff.gz
     Size/MD5:    40454 0d331ab6957f872485bbe36a52bcbfd2
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1.dsc
     Size/MD5:     1160 d4178e19150826c6c1101b16a67cfc67
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12.orig.tar.gz
     Size/MD5:  2464747 141461b9c04e454dc8933c9d1f2abf83

 amd64 architecture (Athlon64, Opteron, EM64T Xeon):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_amd64.udeb
     Size/MD5:   154596 a306db8ee52b32ab4f862ad4784c9390
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_amd64.deb
     Size/MD5:   296866 fca95e99bc1fbf4d33735d5774d082f5

 i386 architecture (x86 compatible Intel/AMD):

   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_i386.udeb
     Size/MD5:   145538 6080b539c186fe8a6bb57bbecf108f95
   http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_i386.deb
     Size/MD5:   289402 78a00423731f5b937087fda628fc251c

 powerpc architecture (Apple Macintosh G3/G4/G5):

   http://ports.ubuntu.com/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_powerpc.udeb
     Size/MD5:   158994 cce4fe5f77fb58eb4cd30ed7cccac07b
   http://ports.ubuntu.com/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_powerpc.deb
     Size/MD5:   301042 aa09b5eeafedd0d5439113bdc47a1bbc

 sparc architecture (Sun SPARC/UltraSPARC):

   http://ports.ubuntu.com/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_sparc.udeb
     Size/MD5:   149686 2505903c358ce719672a01f90312dc8b
   http://ports.ubuntu.com/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_sparc.deb
     Size/MD5:   292668 563284a73f1506acdff6d0540d5745ed
Screenshot

Project Spotlight

WavePacket (C++ version)

A library to solve the Schroedinger equation numerically.

Screenshot

Project Spotlight

Geany

A fast and lightweight IDE using GTK2.