UBUNTU-CVE-2014-4877
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-4877
UBUNTU-CVE-2014-4877
Summary:
Details: Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
References: https://ubuntu.com/security/CVE-2014-4877, http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.html, https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access, https://ubuntu.com/security/notices/USN-2393-1, https://www.cve.org/CVERecord?id=CVE-2014-4877
Affected packages
Package
Name: wget
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
