Vulnerability Name:

CVE-2002-1344 (CCN-10820)

Assigned:2002-12-10
Published:2002-12-10
Updated:2018-10-19
Summary:Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: CCN
Type: SCO Security Advisory CSSA-2003-003.0
wget directory traversal and buffer overrun vulnerabilities

Source: SCO
Type: UNKNOWN
CSSA-2003-003.0

Source: CCN
Type: VulnWatch Mailing List, Tue Dec 10 2002 - 18:22:40 CST
Directory Traversal Vulnerabilities in FTP Clients

Source: VULNWATCH
Type: UNKNOWN
20021210 Directory Traversal Vulnerabilities in FTP Clients

Source: MITRE
Type: CNA
CVE-2002-1344

Source: CONECTIVA
Type: UNKNOWN
CLA-2002:552

Source: CCN
Type: Conectiva Linux Announcement CLSA-2002:552
Directory transversal vulnerability

Source: CONECTIVA
Type: UNKNOWN
CLSA-2002:552

Source: BUGTRAQ
Type: UNKNOWN
20021211 Directory Traversal Vulnerabilities in FTP Clients

Source: BUGTRAQ
Type: UNKNOWN
20021219 TSLSA-2002-0089 - wget

Source: CCN
Type: RHSA-2002-229
Updated wget packages fix directory traversal bug

Source: CCN
Type: RHSA-2002-256
wget security update

Source: CCN
Type: CIAC Information Bulletin N-022
Red Hat Updated wget packages fix directory traversal bug

Source: CIAC
Type: UNKNOWN
N-022

Source: DEBIAN
Type: DSA-209
wget -- directory traversal

Source: CCN
Type: GNU Project Web site
GNU wget

Source: XF
Type: UNKNOWN
wget-ftp-filename-traversal(10820)

Source: CCN
Type: US-CERT VU#210148
wget contains directory traversal vulnerability

Source: CERT-VN
Type: US Government Resource
VU#210148

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2002:086

Source: CCN
Type: Gentoo Linux Security Announcement 200212-7
wget -- directory traversal

Source: CCN
Type: Immunix OS Security Advisory IMNX-2003-7+-011-01
wget

Source: CCN
Type: OpenPKG-SA-2003.007
Wget

Source: OPENPKG
Type: UNKNOWN
OpenPKG-SA-2003.007

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2002:229

Source: REDHAT
Type: UNKNOWN
RHSA-2002:256

Source: CALDERA
Type: UNKNOWN
CSSA-2003.003.0

Source: BID
Type: Patch, Vendor Advisory
6352

Source: CCN
Type: BID-6352
WGet NLST Client Side File Overwriting Vulnerability

Source: BID
Type: UNKNOWN
6360

Source: CCN
Type: BID-6360
Multiple Vendor FTP Client Side File Overwriting Vulnerability

Source: CCN
Type: Trustix Secure Linux Security Advisory #2002-0089
wget -- directory traversal bug

Source: XF
Type: UNKNOWN
wget-ftp-filename-traversal(10820)

Source: DEBIAN
Type: UNKNOWN
DSA-209

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:wget:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.6:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.7:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.8:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.8.2:*:*:*:*:*:*:*
  • OR cpe:/h:sun:cobalt_raq_xtr:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:wget:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.6:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.7:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.8:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.8.1:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:wget:1.8.2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:linux:6.2:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:mandrakesoft:mandrake_single_network_firewall:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:1.5:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:current:*:*:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:1.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:1.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1:*:itanium:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.0:*:ppc:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.1:*:ia64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.2:*:ppc:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20021344
    V
    CVE-2002-1344
    2015-11-16
    oval:org.debian:def:209
    V
    directory traversal
    2002-12-12
    BACK
    gnu wget 1.5.3
    gnu wget 1.6
    gnu wget 1.7
    gnu wget 1.7.1
    gnu wget 1.8
    gnu wget 1.8.1
    gnu wget 1.8.2
    sun cobalt raq xtr *
    gnu wget 1.5.3
    gnu wget 1.6
    gnu wget 1.7
    gnu wget 1.7.1
    gnu wget 1.8
    gnu wget 1.8.1
    gnu wget 1.8.2
    redhat linux 6.2
    debian debian linux 2.2
    mandrakesoft mandrake linux 7.0
    redhat linux 7
    mandrakesoft mandrake linux 7.2
    conectiva linux 6.0
    redhat linux 7.1
    mandrakesoft mandrake linux 8.0
    mandrakesoft mandrake single network firewall 7.2
    conectiva linux 7.0
    trustix secure linux 1.5
    mandrakesoft mandrake linux 8.1
    redhat linux 7.2
    mandrakesoft mandrake linux 8.2
    conectiva linux 8.0
    redhat linux 7.3
    debian debian linux 3.0
    openpkg openpkg current
    gentoo linux *
    redhat linux 8.0
    openpkg openpkg 1.1
    mandrakesoft mandrake linux 9.0
    openpkg openpkg 1.2
    redhat enterprise linux 2.1
    redhat linux advanced workstation 2.1
    mandrakesoft mandrake linux 8.0
    mandrakesoft mandrake linux 8.1
    mandrakesoft mandrake linux 8.2