Skip to main content

GNU Wget Arbitrary Filesystem Access Vulnerability

Last Update Date: 30 Oct 2014 10:20 Release Date: 30 Oct 2014 3055 Views

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

A vulnerability was identified in wget. A remote user can cause arbitrary files, directories, and symlinks to be created on the target user's system.

 

A remote unauthenticated malicious FTP server, connected to the victim via wget, can create and overwrite arbitrary files in the context of the user running wget.


Impact

  • Data Manipulation

System / Technologies affected

  • wget versions 1.15 and earlier

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link