Back

MEDIUM

Wget attempts to dereference NULL pointer upon response from malicious FTP server

Published Dec 23, 2006

Description

The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command.

Affected products

Remediation

Red Hat statement

We do not consider a crash of a client application such as wget to be a security issue. This flaw was fixed in wget shipped in Red Hat Enterprise Linux 5 before the initial release of the product. Version of wget shipped in Red Hat Enterprise Linux 3 and 4 are affected by this bug.

Metrics

Weaknesses (0)

No CWE recorded.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 23, 2006
Updated Aug 7, 2024
Reserved Dec 22, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 18, 2006