Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wget | Aug 30, 2017 | Oct 29, 2014 |
| Centos_linux | — | Upgrade wget | Dec 1, 2016 | Oct 29, 2014 |
| Debian | — | Upgrade wget | Jul 30, 2024 | Oct 29, 2014 |
| Freebsd | — | Upgrade wget | Dec 10, 2025 | Nov 8, 2014 |
| Gentoo Linux | — | Upgrade net-misc/wget. | Oct 30, 2017 | Oct 29, 2014 |
| Oracle Solaris | — | Upgrade web/wget to version 1.16-0.175.2.6.0.1.0 on Solaris 11.2 | May 29, 2017 | Oct 29, 2014 |
| Oracle_linux | — | Upgrade wget | Nov 9, 2016 | Oct 29, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 27, 2014 |
| Suse | — | Upgrade wget-openssl1Upgrade wget | Dec 18, 2015 | Oct 29, 2014 |
| Ubuntu | — | Upgrade wget | Nov 8, 2024 | Oct 29, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub