PT-2005-1138 · Gnu+1 · Wget+1
Published
2005-02-15
·
Updated
2018-10-03
·
CVE-2004-1487
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
wget versions 1.8.x through 1.9.x
Description
The issue allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
Recommendations
For versions 1.8.x through 1.9.x, as a temporary workaround, consider restricting access to redirection URLs until a patch is available. Avoid using wget to access untrusted web servers that may contain malicious redirection URLs.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Wget