CVE-2010-2252
EPSS 3.8%wget - potential code execution
發布日:2010/7/6修改日:2026/4/28
描述
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
受影響套件(2)
- Debian/wgetfrom 0, < 1.12-2.1
- Debian/wgetfrom 0, < 1.11.4-2+lenny2