wget: Lack of filename checking allows arbitrary file upload via FTP redirect
Published Jun 30, 2016
8.8
HIGHCVSS 3.1
EPSS 46.06%
Description
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
Affected products
No data.
Configuration 2
- 12.04
- 14.04
- 15.10
- 16.04
Configuration 4
- ≥ 6.1.0 · ≤ 6.1.16
- ≥ 7.0.0 · ≤ 7.0.14
- ≥ 7.1.0 · ≤ 7.1.9
No data.
Red Hat Enterprise Linux 7
wget-0:1.14-13.el7
Fixed · RHSA-2016:2587
Red Hat Enterprise Linux 5
wget
Will not fix
Red Hat Enterprise Linux 6
wget
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | wget-0:1.14-13.el7 | Fixed | RHSA-2016:2587 |
| Red Hat Enterprise Linux 5 | wget | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | wget | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Use wget with "-O" option to explicitly specify the output filename.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 46.06% (0.46060) | 98.77th | v5 (v2026.06.15) |
| Jun 15, 2026 | 45.93% (0.45935) | 98.65th | v5 (v2026.06.15) |
| Feb 9, 2026 | 74.35% (0.74353) | 98.81th | v4 (v2025.03.14) |
| Dec 1, 2025 | 75.59% (0.75588) | 98.85th | v4 (v2025.03.14) |
| Oct 5, 2025 | 79.09% (0.79093) | 99.03th | v4 (v2025.03.14) |
| Jul 30, 2025 | 75.59% (0.75588) | 98.84th | v4 (v2025.03.14) |
| Jul 13, 2025 | 73.86% (0.73862) | 98.75th | v4 (v2025.03.14) |
| Jul 12, 2025 | 72.29% (0.72288) | 98.67th | v4 (v2025.03.14) |
| Mar 21, 2025 | 73.29% (0.73293) | 98.75th | v4 (v2025.03.14) |
| Mar 17, 2025 | 77.17% (0.77166) | 98.92th | v4 (v2025.03.14) |
| Dec 17, 2024 | 92.64% (0.92641) | 99.24th | v3 (v2023.03.01) |
| Jun 25, 2024 | 95.51% (0.95507) | 99.41th | v3 (v2023.03.01) |
| Apr 22, 2024 | 95.34% (0.95340) | 99.33th | v3 (v2023.03.01) |
| Feb 16, 2024 | 95.73% (0.95734) | 99.36th | v3 (v2023.03.01) |
| Jan 13, 2024 | 95.40% (0.95397) | 99.22th | v3 (v2023.03.01) |
| Jul 8, 2023 | 95.80% (0.95801) | 99.15th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.24% (0.96239) | 99.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 51.28% (0.51276) | 98.74th | v2 (v2022.01.01) |
| Feb 3, 2023 | 51.28% (0.51276) | 98.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 48.05% (0.48051) | 98.10th | v2 (v2022.01.01) |
References (16)
- http://git.savannah.gnu.org/cgit/wget.git/commit/?id=e996e322ffd42aaa051602da182d03178d0f13e1 x_refsource_CONFIRMPatchVendor Advisory
- http://lists.gnu.org/archive/html/info-gnu/2016-06/msg00004.html mailing-listx_refsource_MLISTMailing ListPatchVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00043.html vendor-advisoryx_refsource_SUSEBroken Link
- http://packetstormsecurity.com/files/162395/GNU-wget-Arbitrary-File-Upload-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-2587.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/91530 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036133 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3012-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-4971 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1343666 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-4971
- https://security.gentoo.org/glsa/201610-11 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.paloaltonetworks.com/CVE-2016-4971 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-4971
- https://www.exploit-db.com/exploits/40064/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.