Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-4877

Опубликовано: 29 окт. 2014
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 9.3

Описание

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

РелизСтатусПримечание
devel

released

1.16-1ubuntu1
esm-infra-legacy/trusty

released

1.15-1ubuntu1.14.04.1
lucid

released

1.12-1.1ubuntu2.2
precise

released

1.13.4-2ubuntu1.2
trusty

released

1.15-1ubuntu1.14.04.1
trusty/esm

released

1.15-1ubuntu1.14.04.1
upstream

released

1.16
utopic

released

1.15-1ubuntu1.14.10.1

Показывать по

EPSS

Процентиль: 98%
0.57321
Средний

9.3 Critical

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

nvd
почти 11 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

debian
почти 11 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when re ...

github
больше 3 лет назад

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

oracle-oval
почти 11 лет назад

ELSA-2014-1764: wget security update (MODERATE)

EPSS

Процентиль: 98%
0.57321
Средний

9.3 Critical

CVSS2