ELSA-2016-2587

ELSA-2016-2587 - wget security and bug fix update

Type:SECURITY
Impact:MODERATE
Release Date:2016-11-09

Description


[1.14-13]
- Fix CVE-2016-4971 (#1345778)
- Added support for non-ASCII URLs (Related: CVE-2016-4971)

[1.14-12]
- Fix wget to include Host header on CONNECT as required by HTTP 1.1 (#1203384)
- Run internal test suite during build (#1295846)
- Fix -nv being documented as synonym for two options (#1147572)

[1.14-11]
- Fix CVE-2014-4877 wget: FTP symlink arbitrary filesystem access (#1156136)


Related CVEs


CVE-2016-4971

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (x86_64) wget-1.14-13.el7.src.rpma06b34b3169946643893171a882b478d0345e820b46cef2b9c8ff0836b1dd321ELSA-2019-1228ol7_x86_64_latest_archive
wget-1.14-13.el7.src.rpma06b34b3169946643893171a882b478d0345e820b46cef2b9c8ff0836b1dd321ELSA-2019-1228ol7_x86_64_u3_base
wget-1.14-13.el7.x86_64.rpm632c365b300aad76d1e5aa948af7f6c0718e04e9599805a11eb3adca396f116cELSA-2019-1228ol7_x86_64_latest_archive
wget-1.14-13.el7.x86_64.rpm632c365b300aad76d1e5aa948af7f6c0718e04e9599805a11eb3adca396f116cELSA-2019-1228ol7_x86_64_u3_base



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete