CVE-2004-2014: Low severity gnu wget vulnerability
Published Dec 31, 2004
·Updated
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Affected Software
9 affected components
GNU Wget=1.5.3
GNU Wget=1.6
GNU Wget=1.7
GNU Wget=1.7.1
GNU Wget=1.8
GNU Wget=1.8.1
GNU Wget=1.8.2
GNU Wget=1.9
GNU Wget=1.9.1
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2014?
CVE-2004-2014 has been rated as a moderate severity vulnerability due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2004-2014?
To fix CVE-2004-2014, update Wget to version 1.9.2 or later which includes patches for this vulnerability.
3
Who is affected by CVE-2004-2014?
CVE-2004-2014 affects local users of Wget versions 1.6 through 1.9.1, allowing them to exploit symlink vulnerabilities.
4
What attack vector is utilized in CVE-2004-2014?
CVE-2004-2014 is exploited through a symlink attack on the file name being downloaded.
5
Is CVE-2004-2014 a remote or local vulnerability?
CVE-2004-2014 is classified as a local vulnerability since it requires local user access to exploit.