Red Hat Bugzilla – Bug 1328137
CVE-2016-7098 wget: files rejected by access list are kept on the disk for the duration of HTTP connection
Last modified: 2016-08-29 02:47:16 EDT
A possible vulnerability was found in wget. The vulnerability surfaces when wget is used to download a single file with recursive option (-r / -m) and an access list ( -A ), wget only applies the list at the end of the download process. Although the file get successfully deleted in the end, this creates a race condition situation as an attacker who has control over the URL, could slow down the download process so that he had a chance to make use of the malicious file before it gets deleted.
Public via http://www.openwall.com/lists/oss-security/2016/08/12/2
CVE assignment: http://seclists.org/oss-sec/2016/q3/385