CVE-2014-4877

critical
Published 2014-10-29 · Modified 2026-05-06
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-4877

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — https://bugzilla.redhat.com/show_bug.cgi?id=1139181

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://www.kb.cert.org/vuls/id/685996

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://lists.gnu.org/archive/html/bug-wget/2014-10/msg00150.html

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://git.savannah.gnu.org/cgit/wget.git/commit/?id=b4440d96cf8173d68ecaa07c36b8f4316ee794d0

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2014-4877.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed1.16-1
debian debianbullseyefixed1.16-1
debian debianforkyfixed1.16-1
debian debiansidfixed1.16-1
debian debiantrixiefixed1.16-1

Application impact

VendorProductVersionsFixed
gnuwget{"endIncluding":"1.15"}
gnuwget1.12
gnuwget1.13
gnuwget1.13.1
gnuwget1.13.2
gnuwget1.13.3
gnuwget1.13.4
gnuwget1.14

References

CWEs

CWE-22

Verify integrity in audit chain (admin only). AS-IS.