Description
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
References (17)
Core 17
Core References
Various Sources vendor-advisory
x_refsource_conectiva
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000552
Various Sources vendor-advisory
x_refsource_sco
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-003.0.txt
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2002/dsa-209
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=104033016703851&w=2
Third Party Advisory, US Government Resource third-party-advisory
government-resource
x_refsource_ciac
http://www.ciac.org/ciac/bulletins/n-022.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6360
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2002-256.html
Various Sources vendor-advisory
x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-086.php
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103962838628940&w=2
Vendor Advisory vendor-advisory
x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000552
Patch, Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2002-229.html
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_caldera
http://www.securityfocus.com/archive/1/307045/30/26300/threaded
Third Party Advisory mailing-list
x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0102.html
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6352
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/210148
Third Party Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/10820.php
Vendor Advisory vendor-advisory
x_refsource_openpkg
http://www.openpkg.com/security/advisories/OpenPKG-SA-2003.007.html
Scores
EPSS
0.0090
EPSS Percentile
75.9%
Details
Status
published
Products (8)
gnu/wget
1.5.3
gnu/wget
1.6
gnu/wget
1.7
gnu/wget
1.7.1
gnu/wget
1.8
gnu/wget
1.8.1
gnu/wget
1.8.2
sun/cobalt_raq_xtr
Published
Dec 18, 2002
Tracked Since
Feb 18, 2026