CVE-2014-4877
published 2014-10-29CVE-2014-4877: Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and…
PriorityP269critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
39.88%
98.5th percentile
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.16-1 (bookworm) | wget 1.16-1 (bookworm) |
| gnu | wget | <= 1.15 | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | — | — |
| gnu | wget | >= 0 < 1.16-1 | 1.16-1 |
| gnu | wget | >= 0 < 1.16-1 | 1.16-1 |
| gnu | wget | >= 0 < 1.16-1 | 1.16-1 |
| gnu | wget | >= 0 < 1.16-1 | 1.16-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring FTP LIST responses that contain duplicate filename entries where one entry is a symlink — this is the core attack vector for CVE-2014-4877. ↗
- →Flag invocations of wget using recursive/mirror mode (-r or -m flags) without --retr-symlinks, especially when connecting to untrusted or external FTP servers. ↗
- →Monitor for unexpected symlink creation in directories writable by the user running wget, particularly during FTP recursive downloads — this is the filesystem artifact of successful exploitation. ↗
- →Identify vulnerable wget versions (< 1.16) in use via User-Agent strings in HTTP/FTP traffic or via package inventory; Wget/1.13.4 observed in the wild during exploitation. ↗
- ·The vulnerability is only exploitable when wget is invoked with recursion enabled (-r) or mirror mode (-m). Non-recursive wget usage is not affected. ↗
- ·Adding 'retr-symlinks=on' to /etc/wgetrc or ~/.wgetrc mitigates the vulnerability without upgrading, by preventing local symlink creation during FTP recursive downloads. ↗
- ·Red Hat Enterprise Linux 5 will NOT receive a fix for this CVE due to its Production 3 lifecycle phase; systems on RHEL 5 remain permanently vulnerable unless mitigated manually. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerability
vendor_ubuntu·2014-10-30
CVE-2014-4877 Wget vulnerability
Title: Wget vulnerability
Summary: Wget could be made to overwrite files.
HD Moore discovered that Wget contained a path traversal vulnerability
when downloading symlinks using FTP. A malicious remote FTP server or a man
in the middle could use this issue to cause Wget to overwrite arbitrary
files, possibly leading to arbitrary code execution.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
wget: FTP symlink arbitrary filesystem access
vendor_redhat·2014-10-27·CVSS 9.3
CVE-2014-4877 [CRITICAL] CWE-59 wget: FTP symlink arbitrary filesystem access
wget: FTP symlink arbitrary filesystem access
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
A flaw was found in the way Wget handled symbolic links. A malicious FTP server could allow Wget running in the mirror mode (using the '-m' command line option) to write an arbitrary file to a location writable to by the user running Wget, possibly leading to code execution.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate securit
Debian
CVE-2014-4877: wget - Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is...
vendor_debian·2014·CVSS 9.3
CVE-2014-4877 [CRITICAL] CVE-2014-4877: wget - Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is...
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
Scope: local
bookworm: resolved (fixed in 1.16-1)
bullseye: resolved (fixed in 1.16-1)
forky: resolved (fixed in 1.16-1)
sid: resolved (fixed in 1.16-1)
trixie: resolved (fixed in 1.16-1)
GHSA
GHSA-p2w7-gcfj-5p55: Absolute path traversal vulnerability in GNU Wget before 1
ghsa_unreviewed·2022-05-17
CVE-2014-4877 [HIGH] CWE-22 GHSA-p2w7-gcfj-5p55: Absolute path traversal vulnerability in GNU Wget before 1
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
OSV
CVE-2014-4877: Absolute path traversal vulnerability in GNU Wget before 1
osv·2014-10-29·CVSS 9.3
CVE-2014-4877 [CRITICAL] CVE-2014-4877: Absolute path traversal vulnerability in GNU Wget before 1
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
No detection rules found.
Bugzilla
CVE-2014-4877 wget: FTP symlink arbitrary filesystem access [fedora-all]
bugzilla·2014-10-27·CVSS 9.3
CVE-2014-4877 [CRITICAL] CVE-2014-4877 wget: FTP symlink arbitrary filesystem access [fedora-all]
CVE-2014-4877 wget: FTP symlink arbitrary filesystem access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2014-4877 wget: FTP symlink arbitrary filesystem access
bugzilla·2014-09-08·CVSS 9.3
CVE-2014-4877 [CRITICAL] CVE-2014-4877 wget: FTP symlink arbitrary filesystem access
CVE-2014-4877 wget: FTP symlink arbitrary filesystem access
It was found that wget was susceptible to a symlink attack which could create arbitrary files, directories or symbolic links and set their permissions when retrieving a directory recursively through FTP.
Discussion:
Created attachment 935576
proposed fix
---
Acknowledgements:
Red Hat would like to thank the GNU Wget project for reporting this issue. Upstream acknowledges HD Moore of Rapid7, Inc as the original reporter.
---
Created attachment 936905
updated fix
updated version for the proposed fix
---
Statement:
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future u
arXiv
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
arxiv_fulltext·2024-04-03
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
[1]Litao Li
[1]Steven H. H. Ding
[2]Andrew Walenstein
[3]Philippe Charland
[4]Benjamin C. M. Fung
[1]L1NNA Lab, School of Computing, Queen's University, Canada
[2]BlackBerry Ltd., Canada
[3]Mission Critical Cyber Security Section, Defence R&D Canada
[4]Data Mining and Security (DMaS) Lab, McGill University, Canada
## Abstract
Software vulnerabilities are a challenge in cybersecurity. Manual security patches are often difficult and slow to be deployed, while new vulnerabilities are created. Binary code vulnerability detection is less studied and more complex compared to source code, and this has important practical implications. Deep learning has become an efficient and powe
arXiv
SAFE: Self-Attentive Function Embeddings for Binary Similarity
arxiv_fulltext·2019-12-19
SAFE: Self-Attentive Function Embeddings for Binary Similarity
for Binary Similarity
Luca Massarelli^ , Giuseppe Antonio Di Luna^ , Fabio Petroni^*,
Leonardo Querzoni^ , Roberto Baldoni^
: University of Rome Sapienza. \massarelli, querzoni, baldoni\@diag.uniroma1.it.
: CINI, National Laboratory of Cyber Security. [email protected].
*: Facebook AI Research, [email protected].
## Abstract
The binary similarity problem consists in determining if two functions are similar by only considering their compiled form. Advanced techniques for binary similarity recently gained momentum as they can be applied in several fields, such as copyright disputes, malware analysis, vulnerability detection, etc., and thus have an immediate practical impact. Current solutions compare functions by first transforming their binary code in multi-dimensional vector repres
CTF
bctf / torrent
ctf_writeups·2015·CVSS 9.3
[CRITICAL] bctf / torrent
### Solved by Swappage
Torrent lover was a 235 points worth challenge in BCTF 2015.
The obective was to pwn a web application and read the flag out of it.
Everything started with a form, which would allow you to specify an URL, from which the server
would download a .torrent file, process it, and print out basic torrent informations like files
content, tracker URL and the file name.
The page which was displaying the result was suffering from persistent XSS attack, but this was
simply a disguise to lure in the wrong direction, as the objective was to obtain code execution
on the server.
I quickly set up a web server and started to sniff some traffic, and this lured me, again,
in the wrong direction
In fact the HTTP request coming from the remote application looked like this:
User-Age
http://advisories.mageia.org/MGASA-2014-0431.htmlhttp://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00026.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1764.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1955.htmlhttp://security.gentoo.org/glsa/glsa-201411-05.xmlhttp://www.debian.org/security/2014/dsa-3062http://www.kb.cert.org/vuls/id/685996http://www.mandriva.com/security/advisories?name=MDVSA-2015:121http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/70751http://www.ubuntu.com/usn/USN-2393-1https://bugzilla.redhat.com/show_bug.cgi?id=1139181https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-accesshttps://github.com/rapid7/metasploit-framework/pull/4088https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://kc.mcafee.com/corporate/index?page=content&id=SB10106http://advisories.mageia.org/MGASA-2014-0431.htmlhttp://git.savannah.gnu.org/cgit/wget.git/commit/?id=18b0979357ed7dc4e11d4f2b1d7e0f5932d82aa7http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00026.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1764.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1955.htmlhttp://security.gentoo.org/glsa/glsa-201411-05.xmlhttp://www.debian.org/security/2014/dsa-3062http://www.kb.cert.org/vuls/id/685996http://www.mandriva.com/security/advisories?name=MDVSA-2015:121http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/70751http://www.ubuntu.com/usn/USN-2393-1https://bugzilla.redhat.com/show_bug.cgi?id=1139181https://community.rapid7.com/community/metasploit/blog/2014/10/28/r7-2014-15-gnu-wget-ftp-symlink-arbitrary-filesystem-accesshttps://github.com/rapid7/metasploit-framework/pull/4088https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://kc.mcafee.com/corporate/index?page=content&id=SB10106
2014-10-29
Published