GNU WGet < 1.10.2 Buffer Overflow

high Log Correlation Engine Plugin ID 800982

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

The remote host is using a version of wget that contains a flaw in the way that it handles NTLM authentication data. Specifically, a rogue website that returns malformed data during an NTLM authentication session will be able to execute arbitrary code on the local client machine.

Solution

Upgrade to version 1.10.2 or higher.