Debian 安全报告

DSA-1904-1 wget -- 输入验证不足

报告日期:
2009/10/09
受影响的软件:
wget
可被袭击:
参考的安全性数据库:
在 Debian 臭虫追踪系统中: 臭虫 549293.
在 Mitre's CVE 的目录中: CVE-2009-3490.
更详尽的信息:

Daniel Stenberg 发现 wget,一个使用 HTTP(S) 与 FTP 从网站取回档案的网络实用工具,很容易受到“Null Prefix Attacks Against SSL/TLS Certificates”弱点攻击,这个弱点已在 Blackhat conference 发表了一段时间。这允许攻击者通过精心制作,在 Common Name 栏位注入空位元组 (null byte) 的 ITU-T X.509 凭证,执行不被注意的中间人攻击 (man-in-the-middle attacks)。

对于 oldstable distribution (etch),这个问题已在 1.10.2-2+etch1 版被修正。

对于 stable distribution (lenny),这个问题已在 1.11.4-2+lenny1 版被修正。

对于 testing distribution (squeeze),这问题很快会被修正。

对于 unstable distribution (sid),这个问题已在 1.12-1 版被修正。

我们建议你升级你的 wget 软件包。

修改于:

Debian GNU/Linux 4.0 (etch)

来源:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1.diff.gz
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2.orig.tar.gz
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1.dsc
Alpha:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_amd64.deb
ARM:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_arm.deb
HP Precision:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_hppa.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_ia64.deb
Little-endian MIPS:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_sparc.deb

Debian GNU/Linux 5.0 (lenny)

来源:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1.dsc
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4.orig.tar.gz
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1.diff.gz
Alpha:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_alpha.deb
AMD64:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_amd64.deb
ARM:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_arm.deb
ARM EABI:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_armel.deb
HP Precision:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_hppa.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_ia64.deb
Big-endian MIPS:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_mips.deb
Little-endian MIPS:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_sparc.deb

列出的档案的 MD5 检查可以由 original advisory 取得。