[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] [oCERT-2010-001] multiple http client unexpected download filename vulnerability
From:       Ludwig Nussel <ludwig.nussel () suse ! de>
Date:       2010-05-18 7:50:27
Message-ID: 201005180950.28566.ludwig.nussel () suse ! de
[Download RAW message or body]

Florian Weimer wrote:
> * Daniele Bianco:
> 
> > Additionally, unsafe behaviours have been found in wget and lwp-download in
> > the case of HTTP 3xx redirections during file downloading. The two
> > applications automatically use the URL's filename portion specified in the
> > Location header.
> 
> Thanks.  In another venue, I wrote:
> 
> > The difficult thing is that most likely, there are setups out there
> > which expect this particular behavior.  If we change the default
> > behavior, we need an option in wgetrc to turn back on the old one. 8-(

wget doesn't overwrite existing files by default anyways. Instead it appends a
suffix .1, .2 etc to the newly downloaded file. wget also prints the file name
it used. So IMO it's perfectly fine and useful for wget to take the server
provided file name by default.

cu
Ludwig

-- 
 (o_   Ludwig Nussel
 //\   
 V_/_  http://www.suse.de/
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic