CVE-2014-4877
Summary
| CVE | CVE-2014-4877 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-29 10:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Wget | 1.12 | All | All | All |
| Application | Gnu | Wget | 1.13 | All | All | All |
| Application | Gnu | Wget | 1.13.1 | All | All | All |
| Application | Gnu | Wget | 1.13.2 | All | All | All |
| Application | Gnu | Wget | 1.13.3 | All | All | All |
| Application | Gnu | Wget | 1.13.4 | All | All | All |
| Application | Gnu | Wget | 1.14 | All | All | All |
| Application | Gnu | Wget | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#685996 - GNU Wget creates arbitrary symbolic links during recursive FTP download | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, US Government Resource |
| GNU Wget CVE-2014-4877 Symlink Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| wget.git - GNU Wget | af854a3a-2127-422b-91ae-364da2661108 | git.savannah.gnu.org | Patch |
| wget.git - GNU Wget | af854a3a-2127-422b-91ae-364da2661108 | git.savannah.gnu.org | |
| McAfee KnowledgeBase - McAfee Security Bulletin - Data Loss Prevention hotfix resolves two security issues | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | |
| Oracle Bulletin Board Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Support / Security / Advisories / / MDVSA-2015:121 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Add module for CVE-2014-4877 (Wget) by hmoore-r7 · Pull Request #4088 · rapid7/metasploit-framework · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit |
| Gentoo Linux Documentation -- GNU Wget: Arbitrary code execution | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [Bug-wget] GNU wget 1.16 released | af854a3a-2127-422b-91ae-364da2661108 | lists.gnu.org | Patch |
| Metasploit: R7-2014-15: GNU Wget FTP Symlink Ar... | SecurityStreet | af854a3a-2127-422b-91ae-364da2661108 | community.rapid7.com | Exploit |
| Mageia Advisory: MGASA-2014-0431 - Updated wget packages fix CVE-2014-4877 | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | |
| Debian -- Security Information -- DSA-3062-1 wget | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] SUSE-SU-2014:1408-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Bug 1139181 – CVE-2014-4877 wget: FTP symlink arbitrary filesystem access | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| USN-2393-1: Wget vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] SUSE-SU-2014:1366-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | |
| openSUSE-SU-2014:1380-1: moderate: update for wget | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.