This repository was archived by the owner on Mar 16, 2022. It is now read-only.
1.165.0
·
126 commits
to master
since this release
Notably, this release addresses:
USN-3464-1 Ubuntu Security Notice USN-3464-1:
- CVE-2016-7098: Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
- CVE-2017-13089: stack overflow in HTTP protocol handling
- CVE-2017-13090: heap overflow in HTTP protocol handling
- CVE-2017-6508: CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
-ii wget 1.15-1ubuntu1.14.04.2 amd64 retrieves files from the web
+ii wget 1.15-1ubuntu1.14.04.3 amd64 retrieves files from the web