CVE-2016-7098
published 2016-09-26CVE-2016-7098: Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended…
PriorityP357high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EXPLOIT
EPSS
7.50%
93.8th percentile
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.18-4 (bookworm) | wget 1.18-4 (bookworm) |
| gnu | wget | <= 1.17 | — |
| gnu | wget | >= 0 < 1.18-4 | 1.18-4 |
| gnu | wget | >= 0 < 1.18-4 | 1.18-4 |
| gnu | wget | >= 0 < 1.18-4 | 1.18-4 |
| gnu | wget | >= 0 < 1.18-4 | 1.18-4 |
| gnu | wget | >= 0 < 1.15-1ubuntu1.14.04.3 | 1.15-1ubuntu1.14.04.3 |
| gnu | wget | >= 0 < 1.17.1-1ubuntu1.3 | 1.17.1-1ubuntu1.3 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1LOW
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-57mm-2gj4-2977: Race condition in wget 1
ghsa_unreviewed·2022-05-17
CVE-2016-7098 [HIGH] CWE-362 GHSA-57mm-2gj4-2977: Race condition in wget 1
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
OSV
wget vulnerabilities
osv·2017-10-26·CVSS 8.1
CVE-2017-13089 [HIGH] wget vulnerabilities
wget vulnerabilities
Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wget
incorrectly handled certain HTTP responses. A remote attacker could use
this issue to cause Wget to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090)
Dawid Golunski discovered that Wget incorrectly handled recursive or
mirroring mode. A remote attacker could possibly use this issue to bypass
intended access list restrictions. (CVE-2016-7098)
Orange Tsai discovered that Wget incorrectly handled CRLF sequences in
HTTP headers. A remote attacker could possibly use this issue to inject
arbitrary HTTP headers. (CVE-2017-6508)
OSV
CVE-2016-7098: Race condition in wget 1
osv·2016-09-26·CVSS 8.1
CVE-2016-7098 [HIGH] CVE-2016-7098: Race condition in wget 1
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2017-10-30·CVSS 8.1
CVE-2016-7098 [HIGH] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
USN-3464-1 fixed several vulnerabilities in Wget. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wget
incorrectly handled certain HTTP responses. A remote attacker could use
this issue to cause Wget to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090)
Dawid Golunski discovered that Wget incorrectly handled recursive or
mirroring mode. A remote attacker could possibly use this issue to bypass
intended access list restrictions. (CVE-2016-7098)
Orange Tsai discovered that Wget incorrectly handled CRLF sequences in
HTTP headers. A remo
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2017-10-26·CVSS 8.1
CVE-2016-7098 [HIGH] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wget
incorrectly handled certain HTTP responses. A remote attacker could use
this issue to cause Wget to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090)
Dawid Golunski discovered that Wget incorrectly handled recursive or
mirroring mode. A remote attacker could possibly use this issue to bypass
intended access list restrictions. (CVE-2016-7098)
Orange Tsai discovered that Wget incorrectly handled CRLF sequences in
HTTP headers. A remote attacker could possibly use this issue to inject
arbitrary HTTP headers. (CVE-2017-6508)
Instructions: In general, a standard system update wil
Red Hat
wget: files rejected by access list are kept on the disk for the duration of HTTP connection
vendor_redhat·2016-08-11·CVSS 8.1
CVE-2016-7098 [HIGH] wget: files rejected by access list are kept on the disk for the duration of HTTP connection
wget: files rejected by access list are kept on the disk for the duration of HTTP connection
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Statement: Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.
Package: wget (Red Hat Enterprise Linux 5) - Not affected
Package: wget (Red Hat Enterprise Linux 6) - Not affected
Package: wget (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-7098: wget - Race condition in wget 1.17 and earlier, when used in recursive or mirroring mod...
vendor_debian·2016·CVSS 8.1
CVE-2016-7098 [HIGH] CVE-2016-7098: wget - Race condition in wget 1.17 and earlier, when used in recursive or mirroring mod...
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Scope: local
bookworm: resolved (fixed in 1.18-4)
bullseye: resolved (fixed in 1.18-4)
forky: resolved (fixed in 1.18-4)
sid: resolved (fixed in 1.18-4)
trixie: resolved (fixed in 1.18-4)
No detection rules found.
Bugzilla
CVE-2016-7098 wget: files rejected by access list are kept on the disk for the duration of HTTP connection
bugzilla·2016-04-18·CVSS 8.1
CVE-2016-7098 [HIGH] CVE-2016-7098 wget: files rejected by access list are kept on the disk for the duration of HTTP connection
CVE-2016-7098 wget: files rejected by access list are kept on the disk for the duration of HTTP connection
A possible vulnerability was found in wget. The vulnerability surfaces when wget is used to download a single file with recursive option (-r / -m) and an access list ( -A ), wget only applies the list at the end of the download process.
Although the file get successfully deleted in the end, this creates a race condition situation as an attacker who has control over the URL, could slow down the download process so that he had a chance to make use of the malicious file before it gets deleted.
Discussion:
Public via http://www.openwall.com/lists/oss-security/2016/08/12/2
---
CVE assignment:
http://seclists.org/oss-sec/2016/q3/385
---
Statement:
Red Hat Product Security determin
CTF
web50 / README
ctf_writeups·2017·CVSS 8.1
[HIGH] web50 / README
# B3tterS0ci4lN3twork (web 50)
Hint: try to find some cves
## ENG
[PL](#pl-version)
In the task we get access to some webpage.
We can register and log in.
In this webpage we can send messages to other users and there is a clear XSS in the messages.
This pointed us (and many other players) in wrong direction.
We can also change password and upload avatar, but it takes only `.png/.jpg` files.
Once the hint was released we had to change the approach -> CVE has to be about some real software, webserver, php version etc.
All seemed right, but we decided to check how the avatar is uploaded to the server, and we found out that it is using `wget 1.15`.
It's not the latest version, so it's a good candidate for some know vulnerabilty.
Some looking around and we found: https://legalhackers.com/a
http://lists.gnu.org/archive/html/bug-wget/2016-08/msg00083.htmlhttp://lists.gnu.org/archive/html/bug-wget/2016-08/msg00134.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00044.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00007.htmlhttp://www.openwall.com/lists/oss-security/2016/08/27/2http://www.securityfocus.com/bid/93157https://lists.debian.org/debian-lts-announce/2020/01/msg00031.htmlhttps://www.exploit-db.com/exploits/40824/http://lists.gnu.org/archive/html/bug-wget/2016-08/msg00083.htmlhttp://lists.gnu.org/archive/html/bug-wget/2016-08/msg00134.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00044.htmlhttp://lists.opensuse.org/opensuse-updates/2017-01/msg00007.htmlhttp://www.openwall.com/lists/oss-security/2016/08/27/2http://www.securityfocus.com/bid/93157https://lists.debian.org/debian-lts-announce/2020/01/msg00031.htmlhttps://www.exploit-db.com/exploits/40824/
2016-09-26
Published