Critical Wget2 Flaws Expose Users to Arbitrary File Overwrites and Memory Crashes
ID: e9e5d969-9463-5b1e-9041-13053fbcc1c9
STIX ID: report--e9e5d969-9463-5b1e-9041-13053fbcc1c9
Feed Name: securityonline.info
Two serious security flaws were disclosed in GNU Wget2: a Metalink v3/v4 path traversal (CVE-2025-69194) that can trust attacker-supplied <file name> values and overwrite arbitrary files (potentially enabling remote code execution), and a stack-based buffer overflow (CVE-2025-69195) in filename-sanitization logic that can cause memory corruption or crashes; both are remotely exploitable without authentication and only require a user to download or follow a malicious link, so users should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
