GNU Wget CVE-2010-2252 Arbitrary File Overwrite Vulnerability
BID:65722
Info
GNU Wget CVE-2010-2252 Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 65722 |
| Class: | Design Error |
| CVE: |
CVE-2010-2252 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2014 12:00AM |
| Updated: | Jan 12 2016 02:14AM |
| Credit: | Hank Leininger and Solar Designer. |
| Vulnerable: |
GNU wget 1.11.4 GNU wget 1.10.2 GNU wget 1.10.1 GNU wget 1.10 GNU wget 1.9.1 GNU wget 1.9 GNU wget 1.8.2 GNU wget 1.8.1 GNU wget 1.8 GNU wget 1.7.1 GNU wget 1.7 GNU wget 1.6 GNU wget 1.5.3 GNU wget 1.12 Canonical Ubuntu Linux 9.10 Canonical Ubuntu Linux 9.04 Canonical Ubuntu Linux 8.04 - Lts Canonical Ubuntu Linux 6.06 - Lts Canonical Ubuntu Linux 10.04 - Lts |
| Not Vulnerable: | |
Discussion
GNU Wget CVE-2010-2252 Arbitrary File Overwrite Vulnerability
GNU Wget is prone to an arbitrary file-overwrite vulnerability because it fails to properly sanitize user-supplied data.
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application. Due to the nature of this issue, arbitrary code-execution may be possible.
Note: This issue was previously titled 'Multiple Http Clients and File Transfer Tools Arbitrary File Overwrite Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
GNU Wget 1.12 and prior versions are available.
GNU Wget is prone to an arbitrary file-overwrite vulnerability because it fails to properly sanitize user-supplied data.
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application. Due to the nature of this issue, arbitrary code-execution may be possible.
Note: This issue was previously titled 'Multiple Http Clients and File Transfer Tools Arbitrary File Overwrite Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
GNU Wget 1.12 and prior versions are available.
Exploit / POC
GNU Wget CVE-2010-2252 Arbitrary File Overwrite Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
GNU Wget CVE-2010-2252 Arbitrary File Overwrite Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU Wget CVE-2010-2252 Arbitrary File Overwrite Vulnerability
References:
References: