CVE Vulnerabilities

CVE-2004-1487

Published: Apr 27, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a .. that resolves to the IP address of the malicious server, which bypasses wgets filtering for .. sequences.

Affected Software

NameVendorStart VersionEnd Version
WgetGnu1.8 (including)1.8 (including)
WgetGnu1.8.1 (including)1.8.1 (including)
WgetGnu1.8.2 (including)1.8.2 (including)
WgetGnu1.9 (including)1.9 (including)
WgetGnu1.9.1 (including)1.9.1 (including)
Red Hat Enterprise Linux 3RedHatwget-0:1.10.1-1.30E.1*
Red Hat Enterprise Linux 4RedHatwget-0:1.10.1-2.4E.1*
WgetUbuntudapper*
WgetUbuntudevel*
WgetUbuntuedgy*
WgetUbuntufeisty*

References