CVE-2014-4877
29.10.2014, 10:55
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
| Vendor | Product | Version |
|---|---|---|
| gnu | wget | 𝑥 ≤ 1.15 |
| gnu | wget | 1.12 |
| gnu | wget | 1.13 |
| gnu | wget | 1.13.1 |
| gnu | wget | 1.13.2 |
| gnu | wget | 1.13.3 |
| gnu | wget | 1.13.4 |
| gnu | wget | 1.14 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References