GNU Wget FTP Symlink Remote Code Execution Vulnerability(CVE-2014-4877)

  Severity: CRITICAL
  Advisory Date: JUL 21, 2015

  DESCRIPTION

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1006319

Featured Stories