First published: Mon Sep 26 2016(Updated: )
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wget | <=1.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7098 is classified as a medium severity vulnerability due to its potential to bypass access restrictions.
To fix CVE-2016-7098, upgrade wget to version 1.18 or later which resolves the race condition.
CVE-2016-7098 may allow unauthorized access to files by keeping an HTTP connection open, bypassing intended access controls.
CVE-2016-7098 affects wget versions 1.17 and earlier.
CVE-2016-7098 is a vulnerability that could potentially be exploited by remote servers.