CVE-2014-4877

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
gnuwget
𝑥
≤ 1.15
gnuwget
1.12
gnuwget
1.13
gnuwget
1.13.1
gnuwget
1.13.2
gnuwget
1.13.3
gnuwget
1.13.4
gnuwget
1.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wget
bullseye
1.21-1+deb11u1
fixed
bookworm
1.21.3-1
fixed
sid
1.24.5-2
fixed
trixie
1.24.5-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wget
utopic
Fixed 1.15-1ubuntu1.14.10.1
released
trusty
Fixed 1.15-1ubuntu1.14.04.1
released
precise
Fixed 1.13.4-2ubuntu1.2
released
lucid
Fixed 1.12-1.1ubuntu2.2
released
References