First published: Fri Dec 31 2004(Updated: )
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wget | =1.5.3 | |
Wget | =1.6 | |
Wget | =1.7 | |
Wget | =1.7.1 | |
Wget | =1.8 | |
Wget | =1.8.1 | |
Wget | =1.8.2 | |
Wget | =1.9 | |
Wget | =1.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2014 has been rated as a moderate severity vulnerability due to the potential for local users to overwrite arbitrary files.
To fix CVE-2004-2014, update Wget to version 1.9.2 or later which includes patches for this vulnerability.
CVE-2004-2014 affects local users of Wget versions 1.6 through 1.9.1, allowing them to exploit symlink vulnerabilities.
CVE-2004-2014 is exploited through a symlink attack on the file name being downloaded.
CVE-2004-2014 is classified as a local vulnerability since it requires local user access to exploit.