Debian Security Advisory

DLA-536-1 wget -- LTS security update

Date Reported:
30 Jun 2016
Affected Packages:
wget
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 827003.
In Mitre's CVE dictionary: CVE-2016-4971.
More information:

On a server redirect from HTTP to a FTP resource, wget would trust the HTTP server and uses the name in the redirected URL as the destination filename. This behaviour was changed and now it works similarly as a redirect from HTTP to another HTTP resource so the original name is used as the destination file. To keep the previous behaviour the user must provide --trust-server-names.

For Debian 7 Wheezy, these problems have been fixed in version 1.13.4-3+deb7u3.

We recommend that you upgrade your wget packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS