PT-2005-1138 · Gnu+1 · Wget+1

Published

2005-02-15

·

Updated

2018-10-03

·

CVE-2004-1487

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions wget versions 1.8.x through 1.9.x
Description The issue allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
Recommendations For versions 1.8.x through 1.9.x, as a temporary workaround, consider restricting access to redirection URLs until a patch is available. Avoid using wget to access untrusted web servers that may contain malicious redirection URLs.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1487
RHSA-2005:771
RHSA-2005_771

Affected Products

Red Hat
Wget