=========================================================== Ubuntu Security Notice USN-982-1 September 02, 2010 wget vulnerability CVE-2010-2252 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 9.04 Ubuntu 9.10 Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: wget 1.10.2-1ubuntu1.2 Ubuntu 8.04 LTS: wget 1.10.2-3ubuntu1.2 Ubuntu 9.04: wget 1.11.4-2ubuntu1.2 Ubuntu 9.10: wget 1.11.4-2ubuntu2.1 Ubuntu 10.04 LTS: wget 1.12-1.1ubuntu2.1 In general, a standard system update will make all the necessary changes. ATTENTION: This update changes previous behaviour by ignoring the filename supplied by the server during redirects. To re-enable previous behaviour, use the new --trust-server-names option. Details follow: It was discovered that Wget would use filenames provided by the server when following 3xx redirects. If a user or automated system were tricked into downloading a file from a malicious site, a remote attacker could create the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary code. Updated packages for Ubuntu 6.06 LTS: Source archives: http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2.diff.gz Size/MD5: 15892 cf77f701f7a4e993600edad00efcb22b http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2.dsc Size/MD5: 636 d97a4c2c68465eace270b7e066218d20 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2.orig.tar.gz Size/MD5: 1213056 795fefbb7099f93e2d346b026785c4b8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_amd64.deb Size/MD5: 622210 14e3fe0952664e287ff0f3ad1efdb947 i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_i386.deb Size/MD5: 610956 545ece29bffbd451068ade4aec1f7b3d powerpc architecture (Apple Macintosh G3/G4/G5): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_powerpc.deb Size/MD5: 616878 7f9cd84636c7fcd64ce570a1a213d027 sparc architecture (Sun SPARC/UltraSPARC): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-1ubuntu1.2_sparc.deb Size/MD5: 614284 a8232e9723c4378c4366035c97a3b2b4 Updated packages for Ubuntu 8.04 LTS: Source archives: http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2.diff.gz Size/MD5: 170652 808bbaa03c0ddbc392de9e156e44d70f http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2.dsc Size/MD5: 725 7789909434c005ca0a74ddf4987405ca http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2.orig.tar.gz Size/MD5: 1213056 795fefbb7099f93e2d346b026785c4b8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_amd64.deb Size/MD5: 246336 483cb327b9925c4c4ad660610432eda3 http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_amd64.udeb Size/MD5: 113960 df7a72385e0989cbeb9120dc844644d7 i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_i386.deb Size/MD5: 238342 3b9335d320bceae4b9555d9b74c4040f http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_i386.udeb Size/MD5: 106554 6d8a1ac0eed86310027f5e6145bf6c1f lpia architecture (Low Power Intel Architecture): http://ports.ubuntu.com/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_lpia.deb Size/MD5: 237898 f587451d75d63a81785d7e6629a8c17f http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_lpia.udeb Size/MD5: 106532 6b11a315636f4912cd549b6c168fd3d9 powerpc architecture (Apple Macintosh G3/G4/G5): http://ports.ubuntu.com/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_powerpc.deb Size/MD5: 253578 0b2f81b9117f86a186c16a02c6f495ed http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_powerpc.udeb Size/MD5: 121610 65e64e7f815d0e057d5cbba011aee99a sparc architecture (Sun SPARC/UltraSPARC): http://ports.ubuntu.com/pool/main/w/wget/wget_1.10.2-3ubuntu1.2_sparc.deb Size/MD5: 239594 5fecc36c30a89b2a52b41d83370728b3 http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.10.2-3ubuntu1.2_sparc.udeb Size/MD5: 107364 efb59b7498fe2310245fbe0acd702dda Updated packages for Ubuntu 9.04: Source archives: http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2.diff.gz Size/MD5: 20472 2fe3cb90188edccb119d695b252c52ec http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2.dsc Size/MD5: 1163 46bf0822cb7b2f7e1780e6d55518c5b5 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4.orig.tar.gz Size/MD5: 1475149 69e8a7296c0e12c53bd9ffd786462e87 amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_amd64.deb Size/MD5: 250278 e70c5a94f4784802170d203cfe048dc5 http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_amd64.udeb Size/MD5: 119430 2f4865e3621b3b5e683c7eea8d50bd72 i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_i386.deb Size/MD5: 242184 7ec6ab101f8b54fcd3a4eb4973e8c5ba http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_i386.udeb Size/MD5: 112306 faba926b7c0281a9cba9609ffb116ab2 lpia architecture (Low Power Intel Architecture): http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_lpia.deb Size/MD5: 241654 ebb730a6648fb51800170c6aaa09c26b http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_lpia.udeb Size/MD5: 111472 3bfbbc78255499d97fb0a7417b633b52 powerpc architecture (Apple Macintosh G3/G4/G5): http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_powerpc.deb Size/MD5: 257280 4de44eb570dcbcbd914a05a607eb61ec http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_powerpc.udeb Size/MD5: 126396 53177ed5a04dfdb69d45f514945aacb6 sparc architecture (Sun SPARC/UltraSPARC): http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu1.2_sparc.deb Size/MD5: 244156 bf3de555a18c3bb78b10e866945571fa http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu1.2_sparc.udeb Size/MD5: 113940 8375c1bde59077f34bf11553a5d3a682 Updated packages for Ubuntu 9.10: Source archives: http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1.diff.gz Size/MD5: 20475 c2f5506a48724dbb740f2521c1de4f89 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1.dsc Size/MD5: 1163 361efdd9a29385b4c103204450f47836 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4.orig.tar.gz Size/MD5: 1475149 69e8a7296c0e12c53bd9ffd786462e87 amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_amd64.deb Size/MD5: 250552 8e8cb96704eeaa7da3645fe9c7d8be37 http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_amd64.udeb Size/MD5: 119858 cdb9527d2cb1aa9bacf7b6661e08a165 i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_i386.deb Size/MD5: 242296 faf0ddbc9f3f1f7d5f1bb9bca6b80482 http://security.ubuntu.com/ubuntu/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_i386.udeb Size/MD5: 112514 b5a04f9370035619da4420b48790974c lpia architecture (Low Power Intel Architecture): http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_lpia.deb Size/MD5: 242284 18c9fe76cbff7ad8c0f65416bd56a6ae http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_lpia.udeb Size/MD5: 111900 ddf58cb0f68cdcd55861f5b6f0719447 powerpc architecture (Apple Macintosh G3/G4/G5): http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_powerpc.deb Size/MD5: 256280 babdfe39a32131fcfbdac46025b14fa9 http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_powerpc.udeb Size/MD5: 125580 2a28c607eb2cc0c33a42ecceb9548be0 sparc architecture (Sun SPARC/UltraSPARC): http://ports.ubuntu.com/pool/main/w/wget/wget_1.11.4-2ubuntu2.1_sparc.deb Size/MD5: 244904 e01fe75257425084b8741c59c95c8f22 http://ports.ubuntu.com/pool/universe/w/wget/wget-udeb_1.11.4-2ubuntu2.1_sparc.udeb Size/MD5: 115100 d30c70836434f6dea3cdb47acd0d4b0b Updated packages for Ubuntu 10.04: Source archives: http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1.diff.gz Size/MD5: 40454 0d331ab6957f872485bbe36a52bcbfd2 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1.dsc Size/MD5: 1160 d4178e19150826c6c1101b16a67cfc67 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12.orig.tar.gz Size/MD5: 2464747 141461b9c04e454dc8933c9d1f2abf83 amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_amd64.udeb Size/MD5: 154596 a306db8ee52b32ab4f862ad4784c9390 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_amd64.deb Size/MD5: 296866 fca95e99bc1fbf4d33735d5774d082f5 i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_i386.udeb Size/MD5: 145538 6080b539c186fe8a6bb57bbecf108f95 http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_i386.deb Size/MD5: 289402 78a00423731f5b937087fda628fc251c powerpc architecture (Apple Macintosh G3/G4/G5): http://ports.ubuntu.com/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_powerpc.udeb Size/MD5: 158994 cce4fe5f77fb58eb4cd30ed7cccac07b http://ports.ubuntu.com/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_powerpc.deb Size/MD5: 301042 aa09b5eeafedd0d5439113bdc47a1bbc sparc architecture (Sun SPARC/UltraSPARC): http://ports.ubuntu.com/pool/main/w/wget/wget-udeb_1.12-1.1ubuntu2.1_sparc.udeb Size/MD5: 149686 2505903c358ce719672a01f90312dc8b http://ports.ubuntu.com/pool/main/w/wget/wget_1.12-1.1ubuntu2.1_sparc.deb Size/MD5: 292668 563284a73f1506acdff6d0540d5745ed