From a016c0ce6a1daa791353c8bb54383fb9b71be6ef Mon Sep 17 00:00:00 2001 From: Michael Tremer Date: Sun, 29 Oct 2017 18:33:03 +0000 Subject: [PATCH] wget: Update to 1.19.2 Fixes CVE-2017-13089 A stack-based buffer overflow when processing chunked, encoded HTTP responses was found in wget. By tricking an unsuspecting user into connecting to a malicious HTTP server, an attacker could exploit this flaw to potentially execute arbitrary code. Signed-off-by: Michael Tremer --- lfs/wget | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lfs/wget b/lfs/wget index 8d3d13c275..2c750bf653 100644 --- a/lfs/wget +++ b/lfs/wget @@ -24,7 +24,7 @@ include Config -VER = 1.19.1 +VER = 1.19.2 THISAPP = wget-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_MD5 = d30d82186b93fcabb4116ff513bfa9bd +$(DL_FILE)_MD5 = caabf9727fa429626316619a6369fffa install : $(TARGET) -- 2.39.2