CVE-2002-1565
published 2003-06-16CVE-2002-1565: Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code…
PriorityP421high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.95%
85.7th percentile
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.8.2-8 (bookworm) | wget 1.8.2-8 (bookworm) |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
| gnu | wget | >= 0 < 1.8.2-8 | 1.8.2-8 |
| immunix | immunix | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4q5x-p4gv-j5cj: Buffer overflow in url_filename function for wget 1
ghsa_unreviewed·2022-05-03
CVE-2002-1565 [HIGH] GHSA-4q5x-p4gv-j5cj: Buffer overflow in url_filename function for wget 1
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
OSV
CVE-2002-1565: Buffer overflow in url_filename function for wget 1
osv·2003-06-16·CVSS 7.5
CVE-2002-1565 [HIGH] CVE-2002-1565: Buffer overflow in url_filename function for wget 1
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
Red Hat
security flaw
vendor_redhat·2002-12-12·CVSS 7.5
CVE-2002-1565 [HIGH] security flaw
security flaw
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
Debian
CVE-2002-1565: wget - Buffer overflow in url_filename function for wget 1.8.1 allows attackers to caus...
vendor_debian·2002·CVSS 7.5
CVE-2002-1565 [HIGH] CVE-2002-1565: wget - Buffer overflow in url_filename function for wget 1.8.1 allows attackers to caus...
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
Scope: local
bookworm: resolved (fixed in 1.8.2-8)
bullseye: resolved (fixed in 1.8.2-8)
forky: resolved (fixed in 1.8.2-8)
sid: resolved (fixed in 1.8.2-8)
trixie: resolved (fixed in 1.8.2-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2002-1565 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2002-1565 [HIGH] CVE-2002-1565 security flaw
CVE-2002-1565 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
Bugzilla
CAN-2002-1565 Wget buffer overflow
bugzilla·2003-11-24
[MEDIUM] CAN-2002-1565 Wget buffer overflow
CAN-2002-1565 Wget buffer overflow
A buffer overflow in the url_filename function for wget 1.8.1 allows
attackers to cause a segmentation fault via a long URL. Red Hat does not
believe that this issue is exploitable to allow an attacker to be able
to run arbitrary code. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2002-1565 to this issue.
RHSA-2003:372 in progress
Discussion:
An errata has been issued which should help the problem described in this bug report.
This report is therefore being closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, please follow the link below. You may reopen
this bug report if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2003-3
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-003.0.txtftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000716http://marc.info/?l=bugtraq&m=105474357016184&w=2http://www.debian.org/security/2002/dsa-209http://www.redhat.com/support/errata/RHSA-2003-372.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/10851ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-003.0.txtftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.aschttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000716http://marc.info/?l=bugtraq&m=105474357016184&w=2http://www.debian.org/security/2002/dsa-209http://www.redhat.com/support/errata/RHSA-2003-372.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/10851
2003-06-16
Published