CVE-2004-1487: Medium severity GNU Wget vulnerability
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
Affected Software
Event History
Frequently Asked Questions
What are the risks associated with CVE-2004-1487?
CVE-2004-1487 allows remote attackers to overwrite files on the local system, potentially leading to data loss or system compromise.
How do I remediate CVE-2004-1487?
To fix CVE-2004-1487, upgrade to a newer version of wget that does not contain this vulnerability.
Which versions of wget are affected by CVE-2004-1487?
CVE-2004-1487 affects wget versions 1.8.x and 1.9.x, including specific versions like 1.8.1, 1.8.2, and 1.9.1.
What is the source of the vulnerability in CVE-2004-1487?
The vulnerability in CVE-2004-1487 arises from the lack of proper filtering for ".." sequences in URLs by wget.
Is CVE-2004-1487 a high-risk vulnerability?
While CVE-2004-1487 is serious, its risk level may vary based on the specific system configuration and use cases of wget.