CVE-1999-0402: Medium severity GNU Wget vulnerability
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wget 1.5.3from your environment.Uninstall or disable/remove use of wget 1.5.3. This version follows symlinks and may change permissions of the symlink target instead of the symlink itself.
- Compensating control
Avoid running wget 1.5.3 against untrusted directories or locations that may contain symlinks. Ensure download directories do not contain untrusted symlinks and restrict write permissions to trusted users until a fixed version is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0402?
CVE-1999-0402 is considered a moderate severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-1999-0402?
To fix CVE-1999-0402, upgrade GNU Wget to a version later than 1.5.3 that does not exhibit this vulnerability.
What software is affected by CVE-1999-0402?
CVE-1999-0402 specifically affects GNU Wget version 1.5.3.
What kind of attack can exploit CVE-1999-0402?
CVE-1999-0402 can be exploited through symbolic link manipulation to change file permissions.
Is CVE-1999-0402 still relevant today?
While CVE-1999-0402 is an older vulnerability, it remains relevant for systems still running outdated versions of GNU Wget.