CVE-2010-2252
published 2010-07-06CVE-2010-2252: GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote…
PriorityP339medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.21%
89.8th percentile
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.12-2.1 (bookworm) | wget 1.12-2.1 (bookworm) |
| gnu | wget | <= 1.12 | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | >= 0 < 1.12-2.1 | 1.12-2.1 |
| gnu | wget | >= 0 < 1.12-2.1 | 1.12-2.1 |
| gnu | wget | >= 0 < 1.12-2.1 | 1.12-2.1 |
| gnu | wget | >= 0 < 1.12-2.1 | 1.12-2.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerability
vendor_ubuntu·2010-09-02
CVE-2010-2252 Wget vulnerability
Title: Wget vulnerability
It was discovered that Wget would use filenames provided by the server when
following 3xx redirects. If a user or automated system were tricked into
downloading a file from a malicious site, a remote attacker could create
the file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
ATTENTION: This update changes previous behaviour by ignoring the filename
supplied by the server during redirects. To re-enable previous behaviour,
use the new --trust-server-names option.
Red Hat
wget: multiple HTTP client download filename vulnerability [OCERT 2010-001]
vendor_redhat·2010-05-17·CVSS 6.8
CVE-2010-2252 [MEDIUM] wget: multiple HTTP client download filename vulnerability [OCERT 2010-001]
wget: multiple HTTP client download filename vulnerability [OCERT 2010-001]
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact due to the series of events required to successfully exploit it, and is not currently planned to be addressed in future updates. For additional i
Debian
CVE-2010-2252: wget - GNU Wget 1.12 and earlier uses a server-provided filename instead of the origina...
vendor_debian·2010·CVSS 6.8
CVE-2010-2252 [MEDIUM] CVE-2010-2252: wget - GNU Wget 1.12 and earlier uses a server-provided filename instead of the origina...
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Scope: local
bookworm: resolved (fixed in 1.12-2.1)
bullseye: resolved (fixed in 1.12-2.1)
forky: resolved (fixed in 1.12-2.1)
sid: resolved (fixed in 1.12-2.1)
trixie: resolved (fixed in 1.12-2.1)
GHSA
GHSA-hqjw-x4mf-w7v2: GNU Wget 1
ghsa_unreviewed·2022-05-17
CVE-2010-2252 [MEDIUM] CWE-20 GHSA-hqjw-x4mf-w7v2: GNU Wget 1
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
OSV
CVE-2010-2252: GNU Wget 1
osv·2010-07-06·CVSS 6.8
CVE-2010-2252 [MEDIUM] CVE-2010-2252: GNU Wget 1
GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.
Suricata
GPL EXPLOIT fpcount access
suricata·2010-09-23
CVE-1999-1376 GPL EXPLOIT fpcount access
GPL EXPLOIT fpcount access
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT fpcount access"; flow:established,to_server; http.uri; content:"/fpcount.exe"; nocase; reference:bugtraq,2252; reference:cve,1999-1376; classtype:web-application-activity; sid:2101013; rev:13; metadata:created_at 2010_09_23, cve CVE_1999_1376, signature_severity Major, updated_at 2024_03_08;)
No public exploits indexed.
Bugzilla
CVE-2010-3842 mingw32-curl: Did not strip directory parts separated by backslashes, when downloading files
bugzilla·2010-10-13·CVSS 7.5
CVE-2010-3842 [HIGH] CVE-2010-3842 mingw32-curl: Did not strip directory parts separated by backslashes, when downloading files
CVE-2010-3842 mingw32-curl: Did not strip directory parts separated by backslashes, when downloading files
cURL did not properly cut off directory parts from user provided
file name to be downloaded on operating systems, where backslashes
are used to separate directories and file names. This could allow
remote servers to create or overwrite files via a Content-Disposition
header that suggests a crafted filename, and possibly execute arbitrary
code as a consequence of writing to a certain file in a user's home
directory. Different vulnerability than CVE-2010-2251, CVE-2010-2252
and CVE-2010-2253.
Note: As already mentioned in [2]. This flaw only affected those
operating systems, where backslash is used to separate directories
and file names, thus Microsoft Windows, Novell Netware, MSDOS,
Bugzilla
CVE-2010-2252 wget: multiple HTTP client download filename vulnerability [OCERT 2010-001]
bugzilla·2010-06-10·CVSS 6.8
CVE-2010-2252 [MEDIUM] CVE-2010-2252 wget: multiple HTTP client download filename vulnerability [OCERT 2010-001]
CVE-2010-2252 wget: multiple HTTP client download filename vulnerability [OCERT 2010-001]
+++ This bug was initially created as a clone of Bug #591580 +++
The draft advisory from oCERT follows:
The lftp, wget and lwp-download applications are ftp/http clients and file
transfer tools supporting various network protocols. The lwp-download
script is shipped along with the libwww-perl library.
Unsafe behaviours have been found in lftp and lwp-download handling the
Content-Disposition header in conjunction with the 'suggested filename'
functionality.
Additionally unsafe behaviours have been found in wget and lwp-download in
case of HTTP 3xx redirections during file dowloading. The two applications
automatically use the URL's filename portion specified in the Location
header.
Implicitly tr
Bugzilla
CVE-2010-2251 lftp: multiple HTTP client download filename vulnerability [OCERT 2010-001]
bugzilla·2010-05-12·CVSS 7.5
CVE-2010-2251 [HIGH] CVE-2010-2251 lftp: multiple HTTP client download filename vulnerability [OCERT 2010-001]
CVE-2010-2251 lftp: multiple HTTP client download filename vulnerability [OCERT 2010-001]
The draft advisory from oCERT follows:
The lftp, wget and lwp-download applications are ftp/http clients and file
transfer tools supporting various network protocols. The lwp-download
script is shipped along with the libwww-perl library.
Unsafe behaviours have been found in lftp and lwp-download handling the
Content-Disposition header in conjunction with the 'suggested filename'
functionality.
Additionally unsafe behaviours have been found in wget and lwp-download in
case of HTTP 3xx redirections during file dowloading. The two applications
automatically use the URL's filename portion specified in the Location
header.
Implicitly trusting the suggested filenames results in a saved file that
differ
http://lists.gnu.org/archive/html/bug-wget/2010-05/msg00023.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00031.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00032.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00033.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00034.htmlhttp://marc.info/?l=oss-security&m=127411372529485&w=2http://marc.info/?l=oss-security&m=127412569216380&w=2http://marc.info/?l=oss-security&m=127416905831994&w=2http://marc.info/?l=oss-security&m=127422615924593&w=2http://marc.info/?l=oss-security&m=127427572721591&w=2http://marc.info/?l=oss-security&m=127432968701342&w=2http://marc.info/?l=oss-security&m=127441275821210&w=2http://marc.info/?l=oss-security&m=127611288927500&w=2http://rhn.redhat.com/errata/RHSA-2014-0151.htmlhttp://www.ocert.org/advisories/ocert-2010-001.htmlhttp://www.securityfocus.com/bid/65722https://bugzilla.redhat.com/show_bug.cgi?id=591580https://bugzilla.redhat.com/show_bug.cgi?id=602797http://lists.gnu.org/archive/html/bug-wget/2010-05/msg00023.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00031.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00032.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00033.htmlhttp://lists.gnu.org/archive/html/bug-wget/2010-05/msg00034.htmlhttp://marc.info/?l=oss-security&m=127411372529485&w=2http://marc.info/?l=oss-security&m=127412569216380&w=2http://marc.info/?l=oss-security&m=127416905831994&w=2http://marc.info/?l=oss-security&m=127422615924593&w=2http://marc.info/?l=oss-security&m=127427572721591&w=2http://marc.info/?l=oss-security&m=127432968701342&w=2http://marc.info/?l=oss-security&m=127441275821210&w=2http://marc.info/?l=oss-security&m=127611288927500&w=2http://rhn.redhat.com/errata/RHSA-2014-0151.htmlhttp://www.ocert.org/advisories/ocert-2010-001.htmlhttp://www.securityfocus.com/bid/65722https://bugzilla.redhat.com/show_bug.cgi?id=591580https://bugzilla.redhat.com/show_bug.cgi?id=602797
2010-07-06
Published