Lucene search

K
redhatcveRedhat.comRH:CVE-2016-4971
HistoryJun 14, 2016 - 8:18 a.m.

CVE-2016-4971

2016-06-1408:18:41
redhat.com
access.redhat.com
18

EPSS

0.955

Percentile

99.4%

It was found that wget used a file name provided by the server for the downloaded file when following a HTTP redirect to a FTP server resource. This could cause wget to create a file with a different name than expected, possibly allowing the server to execute arbitrary code on the client.

Mitigation

Use wget with "-O" option to explicitly specify the output filename.