[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-442 ---- wget

ID: oval:org.secpod.oval:def:1600121Date: (C)2016-01-19   (M)2022-10-10
Class: PATCHFamily: unix




Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

Platform:
Amazon Linux AMI
Product:
wget
Reference:
ALAS-2014-442
CVE-2014-4877
CVE    1
CVE-2014-4877
CPE    6
cpe:/o:amazon:linux
cpe:/a:gnu:wget:1.12
cpe:/a:gnu:wget
cpe:/a:gnu:wget:1.13
...

© SecPod Technologies