Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 12:39:34 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2041317475&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2Ffiledesc%2FMDVSA-2010-170.txt.html%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2041317475.1338208774.1338208774.1338208774.1%3B%2B__utmz%3D32867617.1338208774.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Mandriva Linux Security Advisory 2010-170 http://packetstormsecurity.org/files/93468/MDVSA-2010-170.txt http://packetstormsecurity.org/files/93468/MDVSA-2010-170.txt http://packetstormsecurity.org/files/93468/Mandriva-Linux-Security-Advisory-2010-170.html Fri, 03 Sep 2010 03:47:14 GMT Mandriva Linux Security Advisory 2010-170 - GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a.wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.