« List of all CVEs

CVE-2010-2252

Published: 7/6/2010 Last updated: 8/7/2024 Reserved: 6/9/2010

GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-wget

Products affected (1)

Product Vendor Version
n/a n/a QCS8550

References (36)