First published: Tue Feb 15 2005(Updated: )
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wget | =1.8 | |
Wget | =1.8.1 | |
Wget | =1.8.2 | |
Wget | =1.9 | |
Wget | =1.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1488 is considered a moderate severity vulnerability due to the potential for arbitrary code execution via terminal escape sequences.
To fix CVE-2004-1488, upgrade to a version of wget that is not affected, specifically versions later than 1.9.1.
CVE-2004-1488 affects GNU Wget versions 1.8.x and 1.9.x.
CVE-2004-1488 allows remote web servers to inject terminal escape sequences due to improper filtering of control characters.
Mitigation for CVE-2004-1488 includes avoiding the use of vulnerable wget versions and ensuring secure usage practices when interacting with untrusted sources.