CVE-2014-4877
Estado: ModificadaAlta (9.3)—
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 40%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://advisories.mageia.org/MGASA-2014-0431.html
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0
- http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.html
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00009.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00026.html
- http://rhn.redhat.com/errata/RHSA-2014-1764.html
- http://rhn.redhat.com/errata/RHSA-2014-1955.html
- http://security.gentoo.org/glsa/glsa-201411-05.xml
- http://www.debian.org/security/2014/dsa-3062
- http://www.kb.cert.org/vuls/id/685996
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:121
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.securityfocus.com/bid/70751
- http://www.ubuntu.com/usn/USN-2393-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1139181
- https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access
- https://github.com/rapid7/metasploit-framework/pull/4088
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://kc.mcafee.com/corporate/index?page=content&id=SB10106
- http://advisories.mageia.org/MGASA-2014-0431.html
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0
- http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.html
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00009.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00026.html
- http://rhn.redhat.com/errata/RHSA-2014-1764.html
- http://rhn.redhat.com/errata/RHSA-2014-1955.html
- http://security.gentoo.org/glsa/glsa-201411-05.xml
- http://www.debian.org/security/2014/dsa-3062
- http://www.kb.cert.org/vuls/id/685996
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:121
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.securityfocus.com/bid/70751
- http://www.ubuntu.com/usn/USN-2393-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1139181
- https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access
- https://github.com/rapid7/metasploit-framework/pull/4088
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://kc.mcafee.com/corporate/index?page=content&id=SB10106
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-4877",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-10-29T10:55:05.417",
"references": [
{
"url": "http://advisories.mageia.org/MGASA-2014-0431.html",
"source": "cret@cert.org"
},
{
"url": "http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7",
"source": "cret@cert.org"
},
{
"url": "http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0",
"tags": [
"Patch"
],
"source": "cret@cert.org"
},
{
"url": "http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.html",
"tags": [
"Patch"
],
"source": "cret@cert.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00004.html",
"source": "cret@cert.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00009.html",
"source": "cret@cert.org"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00026.html",
"source": "cret@cert.org"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1764.html",
"source": "cret@cert.org"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1955.html",
"source": "cret@cert.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-201411-05.xml",
"source": "cret@cert.org"
},
{
"url": "http://www.debian.org/security/2014/dsa-3062",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/685996",
"tags": [
"Patch",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:121",
"source": "cret@cert.org"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html",
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/70751",
"source": "cret@cert.org"
},
{
"url": "http://www.ubuntu.com/usn/USN-2393-1",
"source": "cret@cert.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1139181",
"tags": [
"Patch"
],
"source": "cret@cert.org"
},
{
"url": "https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access",
"tags": [
"Exploit"
],
"source": "cret@cert.org"
},
{
"url": "https://github.com/rapid7/metasploit-framework/pull/4088",
"tags": [
"Exploit"
],
"source": "cret@cert.org"
},
{
"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
"source": "cret@cert.org"
},
{
"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
"source": "cret@cert.org"
},
{
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10106",
"source": "cret@cert.org"
},
{
"url": "http://advisories.mageia.org/MGASA-2014-0431.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.html",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00004.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00009.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00026.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1764.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-1955.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-201411-05.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2014/dsa-3062",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/685996",
"tags": [
"Patch",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:121",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/70751",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-2393-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1139181",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-access",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/rapid7/metasploit-framework/pull/4088",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10106",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink."
},
{
"lang": "es",
"value": "Vulnerabilidad de salto de ruta absoluta en GNU Wget anterior a 1.16, cuando la recursión esta habilitada, permite a servidores FTP remotos escribir a ficheros arbitrarios, y como consecuencia ejecutar código arbitrario, a través de una respuesta LIST que hace referencia al mismo nombre de fichero dentro de dos entradas, una de las cuales indica que el nombre de fichero es para un enlace simbólico."
}
],
"lastModified": "2026-06-17T00:10:43.870",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC092879-65CD-4F25-80DA-70514D6B2A6E",
"versionEndIncluding": "1.15"
},
{
"criteria": "cpe:2.3:a:gnu:wget:1.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5E5E724-5DC7-4264-BF3D-27CFB093AC03"
},
{
"criteria": "cpe:2.3:a:gnu:wget:1.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17D42285-E640-4EF9-8E1A-072C77F6A9C6"
},
{
"criteria": "cpe:2.3:a:gnu:wget:1.13.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB7F0263-11A7-4E85-8A5D-FB41F6CDF784"
},
{
"criteria": "cpe:2.3:a:gnu:wget:1.13.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "244D4F9A-4697-4DF2-9590-36203F19DA63"
},
{
"criteria": "cpe:2.3:a:gnu:wget:1.13.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BE195AF-F305-4B47-8047-C20B1CB6BF31"
},
{
"criteria": "cpe:2.3:a:gnu:wget:1.13.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC6F6840-CAA0-422D-89CF-920D8314A27B"
},
{
"criteria": "cpe:2.3:a:gnu:wget:1.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D225A5FC-7BA8-4DD8-9A9F-6AAA3D15A8A2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}