CVE-2006-6719

Description

From CVE.org

The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command.

Statement

We do not consider a crash of a client application such as wget to be a security issue.

This flaw was fixed in wget shipped in Red Hat Enterprise Linux 5 before the initial release of the product. Version of wget shipped in Red Hat Enterprise Linux 3 and 4 are affected by this bug.

Frequently Asked Questions

Want to get errata notifications? Sign up here.