HTTP: GNU Wget CVE-2016-7098 Security Bypass

This signature detects attempts to exploit a known vulnerability against GNU Wget. An attacker can exploit this issue to bypass the security mechanism and perform unauthorized actions.

Extended Description

Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.

Affected Products

Gnu wget

References

BugTraq: 93157

CVE: CVE-2016-7098

Short Name
HTTP:GNU-WGET-SB
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Bypass CVE-2016-7098 GNU Security Wget bid:93157
Release Date
01/19/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Gnu

CVSS Score

6.8

Found a potential security threat?