ALAS2-2018-1121

Related Vulnerabilities: CVE-2018-0494  

A cookie injection flaw was found in wget. An attacker can create a malicious website which, when accessed, overrides cookies belonging to arbitrary domains.(CVE-2018-0494)

ALAS2-2018-1121


Amazon Linux 2 Security Advisory: ALAS-2018-1121
Advisory Release Date: 2018-12-06 20:27 Pacific
Advisory Updated Date: 2018-12-08 01:50 Pacific
Severity: Medium
References: CVE-2018-0494 

Issue Overview:

A cookie injection flaw was found in wget. An attacker can create a malicious website which, when accessed, overrides cookies belonging to arbitrary domains.(CVE-2018-0494)


Affected Packages:

wget


Issue Correction:
Run yum update wget to update your system.

New Packages:
aarch64:
    wget-1.14-18.amzn2.aarch64
    wget-debuginfo-1.14-18.amzn2.aarch64

i686:
    wget-1.14-18.amzn2.i686
    wget-debuginfo-1.14-18.amzn2.i686

src:
    wget-1.14-18.amzn2.src

x86_64:
    wget-1.14-18.amzn2.x86_64
    wget-debuginfo-1.14-18.amzn2.x86_64