oss-sec mailing list archives

Re: [oCERT-2010-001] multiple http client unexpected download filename vulnerability


From: "Steven M. Christey" <coley () linus mitre org>
Date: Wed, 9 Jun 2010 15:47:42 -0400 (EDT)


On Wed, 9 Jun 2010, Marcus Meissner wrote:

On Mon, May 17, 2010 at 01:03:22PM +0100, Daniele Bianco wrote:

#2010-001 multiple http client unexpected download filename vulnerability

Description:

The lftp, wget and lwp-download applications are ftp/http clients and file
transfer tools supporting various network protocols. The lwp-download
script is shipped along with the libwww-perl library.

Did anyone assign CVE ids for these?

Apologies to oCERT and everyone else for being so terrible at handling this.

CVE-2010-2251 - lftp
CVE-2010-2252 - wget CVE-2010-2253 - libwww-perl as used in lwp-download


- Steve


Current thread: