ALAS-2017-881


Amazon Linux 1 (EOL) Security Advisory: ALAS-2017-881
Advisory Released Date: 2017-08-31
Advisory Updated Date: 2017-08-31
Severity: Low

Issue Overview:

CRLF injection in the url_parse function in url.c
A CRLF injection flaw was found in the way wget handled URLs. A remote attacker could use this flaw to inject arbitrary HTTP headers in requests, via CRLF sequences in the host sub-component of a URL, by tricking a user running wget into processing crafted URLs. (CVE-2017-6508)


Affected Packages:

wget


Issue Correction:
Run yum update wget to update your system.

New Packages:
i686:
    wget-debuginfo-1.18-3.27.amzn1.i686
    wget-1.18-3.27.amzn1.i686

src:
    wget-1.18-3.27.amzn1.src

x86_64:
    wget-1.18-3.27.amzn1.x86_64
    wget-debuginfo-1.18-3.27.amzn1.x86_64