CVE-2016-7098: Race Condition
Published Sep 26, 2016
·Updated
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Affected Software
1 affected component
GNU Wget<=1.17
Event History
Sep 26, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7098?
CVE-2016-7098 is classified as a medium severity vulnerability due to its potential to bypass access restrictions.
2
How do I fix CVE-2016-7098?
To fix CVE-2016-7098, upgrade wget to version 1.18 or later which resolves the race condition.
3
What impact does CVE-2016-7098 have on my system?
CVE-2016-7098 may allow unauthorized access to files by keeping an HTTP connection open, bypassing intended access controls.
4
Which versions of wget are affected by CVE-2016-7098?
CVE-2016-7098 affects wget versions 1.17 and earlier.
5
Is CVE-2016-7098 an exploit or a vulnerability?
CVE-2016-7098 is a vulnerability that could potentially be exploited by remote servers.