CVE Vulnerabilities

CVE-2002-1344

Published: Dec 18, 2002 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

Affected Software

Name Vendor Start Version End Version
Wget Gnu 1.5.3 (including) 1.5.3 (including)
Wget Gnu 1.6 (including) 1.6 (including)
Wget Gnu 1.7 (including) 1.7 (including)
Wget Gnu 1.7.1 (including) 1.7.1 (including)
Wget Gnu 1.8 (including) 1.8 (including)
Wget Gnu 1.8.1 (including) 1.8.1 (including)
Wget Gnu 1.8.2 (including) 1.8.2 (including)
Cobalt_raq_xtr Sun * *
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Linux 6.2 RedHat *
Red Hat Linux 7.0 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.2 RedHat *
Red Hat Linux 7.3 RedHat *
Red Hat Linux 8.0 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *

References