High severity8.8NVD Advisory· Published Jun 30, 2016· Updated May 6, 2026
CVE-2016-4971
CVE-2016-4971
Description
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
Affected products
8cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- git.savannah.gnu.org/cgit/wget.git/commit/nvdPatchVendor Advisory
- lists.gnu.org/archive/html/info-gnu/2016-06/msg00004.htmlnvdMailing ListPatchVendor Advisory
- packetstormsecurity.com/files/162395/GNU-wget-Arbitrary-File-Upload-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingPatchThird Party Advisory
- www.exploit-db.com/exploits/40064/nvdExploitThird Party AdvisoryVDB Entry
- www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/91530nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1036133nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-3012-1nvdThird Party Advisory
- security.gentoo.org/glsa/201610-11nvdThird Party Advisory
- security.paloaltonetworks.com/CVE-2016-4971nvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2016-08/msg00043.htmlnvdBroken Link
- rhn.redhat.com/errata/RHSA-2016-2587.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.