Related Vulnerabilities: CVE-2017-13090  

A heap-based buffer overflow has been found in the HTTP protocol handling code of wget < 1.19.2, when processing chunked encoded HTTP responses. By tricking an unsuspecting user into connecting to a malicious HTTP server, an attacker could exploit this flaw to potentially execute arbitrary code.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

A heap-based buffer overflow has been found in the HTTP protocol handling code of wget < 1.19.2, when processing chunked encoded HTTP responses. By tricking an unsuspecting user into connecting to a malicious HTTP server, an attacker could exploit this flaw to potentially execute arbitrary code.

AVG-473 wget 1.19.1-2 1.19.2-1 Critical Fixed

29 Oct 2017 ASA-201710-34 AVG-473 wget Critical multiple issues

https://bugzilla.redhat.com/show_bug.cgi?id=1505445
https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ba6b44f6745b14dce414761a8e4b35d31b176bba