Created attachment 171627 [details] Patch VuXML for wget vuln announcement CVE-2016-4971 HTTP to a FTP redirection file name confusion vulnerability in wget. On a server redirect from HTTP to a FTP resource, wget would trust the HTTP server and uses the name in the redirected URL as the destination filename. * Upstream Announcement (part of 1.18 release announcement): http://lists.gnu.org/archive/html/info-gnu/2016-06/msg00004.html * Upstream commit that fixes it: http://git.savannah.gnu.org/cgit/wget.git/commit/?id=e996e322ffd42aaa051602da182d03178d0f13e1
A commit references this bug: Author: vd Date: Tue Jun 21 08:16:47 UTC 2016 New revision: 417190 URL: https://svnweb.freebsd.org/changeset/ports/417190 Log: Document ftp/wget's HTTP to FTP redirection file name confusion vulnerability PR: 210420 Submitted by: Vladimir Krstulja <vlad-fbsd@acheronmedia.com> Security: CVE-2016-4971 Changes: head/security/vuxml/vuln.xml
Committed, thanks!