Debian 安全警报
DSA-1904-1 wget -- 输入验证不足
- 报告日期:
- 2009/10/09
- 受影响的软件:
- wget
- 可被袭击:
- 是
- 参考的安全性数据库:
- 在 Debian 臭虫追踪系统中: 臭虫 549293.
在 Mitre's CVE 的目录中: CVE-2009-3490. - 更详尽的信息:
-
Daniel Stenberg 发现 wget,一个使用 HTTP(S) 与 FTP 从网站取回档案的网络实用工具,很容易受到“Null Prefix Attacks Against SSL/TLS Certificates”弱点攻击,这个弱点已在 Blackhat conference 发表了一段时间。这允许攻击者通过精心制作,在 Common Name 栏位注入空位元组 (null byte) 的 ITU-T X.509 凭证,执行不被注意的中间人攻击 (man-in-the-middle attacks)。
对于 oldstable distribution (etch),这个问题已在 1.10.2-2+etch1 版被修正。
对于 stable distribution (lenny),这个问题已在 1.11.4-2+lenny1 版被修正。
对于 testing distribution (squeeze),这问题很快会被修正。
对于 unstable distribution (sid),这个问题已在 1.12-1 版被修正。
我们建议你升级你的 wget 软件包。
- 修改于:
-
Debian GNU/Linux 4.0 (etch)
- 来源:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1.diff.gz
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2.orig.tar.gz
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1.dsc
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2.orig.tar.gz
- Alpha:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_alpha.deb
- AMD64:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_amd64.deb
- ARM:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_arm.deb
- HP Precision:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_hppa.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_ia64.deb
- Little-endian MIPS:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.10.2-2+etch1_sparc.deb
Debian GNU/Linux 5.0 (lenny)
- 来源:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1.dsc
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4.orig.tar.gz
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1.diff.gz
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4.orig.tar.gz
- Alpha:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_alpha.deb
- AMD64:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_amd64.deb
- ARM:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_arm.deb
- ARM EABI:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_armel.deb
- HP Precision:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_hppa.deb
- Intel IA-32:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_i386.deb
- Intel IA-64:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_ia64.deb
- Big-endian MIPS:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_mips.deb
- Little-endian MIPS:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_mipsel.deb
- PowerPC:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_powerpc.deb
- IBM S/390:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_s390.deb
- Sun Sparc:
- http://security.debian.org/pool/updates/main/w/wget/wget_1.11.4-2+lenny1_sparc.deb
列出的档案的 MD5 检查可以由 original advisory 取得。