Unrated severityNVD Advisory· Published Oct 29, 2014· Updated May 6, 2026
CVE-2014-4877
CVE-2014-4877
Description
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
Affected products
8cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*range: <=1.15
- cpe:2.3:a:gnu:wget:1.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:wget:1.13:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:wget:1.13.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:wget:1.13.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:wget:1.13.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:wget:1.13.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:wget:1.14:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- git.savannah.gnu.org/cgit/wget.git/commit/nvdPatch
- lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.htmlnvdPatch
- www.kb.cert.org/vuls/id/685996nvdPatchUS Government Resource
- bugzilla.redhat.com/show_bug.cginvdPatch
- community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-accessnvdExploit
- github.com/rapid7/metasploit-framework/pull/4088nvdExploit
- advisories.mageia.org/MGASA-2014-0431.htmlnvd
- git.savannah.gnu.org/cgit/wget.git/commit/nvd
- lists.opensuse.org/opensuse-security-announce/2014-11/msg00004.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-11/msg00009.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-11/msg00026.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-1764.htmlnvd
- rhn.redhat.com/errata/RHSA-2014-1955.htmlnvd
- security.gentoo.org/glsa/glsa-201411-05.xmlnvd
- www.debian.org/security/2014/dsa-3062nvd
- www.mandriva.com/security/advisoriesnvd
- www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlnvd
- www.securityfocus.com/bid/70751nvd
- www.ubuntu.com/usn/USN-2393-1nvd
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvd
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvd
- kc.mcafee.com/corporate/indexnvd
News mentions
0No linked articles in our index yet.