¡¾¸´ÏÖ¡¿GNU Wget2 Ŀ¼´©Ô½Îó²î£¨CVE-2025-69194£©

Ðû²¼Ê±¼ä 2026-01-06

GNU Wget2ÊǾ­µäÏÂÔØ¹¤¾ßWgetµÄÏÖ´ú»¯¼ÌÈÎÕߣ¬£¬£¬£¬£¬Ëüͨ¹ý¶àÏ̡߳¢HTTP/2Ö§³Ö¼°µÝ¹éÏÂÔØ¹¦Ð§£¬£¬£¬£¬£¬ÌṩÁ˸ü¸ßЧ¡¢¸ü¿ìËÙµÄÏÂÁîÐÐÏÂÔØÌåÑé¡£¡£¡£¡£


MetalinkÊÇÒ»ÖÖ»ùÓÚXMLµÄÔªÊý¾ÝÎļþÃûÌ㬣¬£¬£¬£¬Ëü½«Ò»¸öÎļþµÄ¶à¸öÏÂÔØ¾µÏñµØµãºÍУÑéÐÅÏ¢ÕûºÏÔÚÒ»Æð£¬£¬£¬£¬£¬ÈÃÏÂÔØ¹¤¾ßÄÜʵÏÖ×Ô¶¯·À´í¡¢Ð£ÑéÒÔ¼°¿çЧÀÍÆ÷µÄ·Ö¶Î¼ÓËÙÏÂÔØ¡£¡£¡£¡£


2025Äê12ÔÂ28ÈÕ£¬£¬£¬£¬£¬GNUÐû²¼Á˸üУ¬£¬£¬£¬£¬ÐÞ¸´ÁËGNU Wget2ÖÐͨ¹ýMetalinkĿ¼´©Ô½¾ÙÐÐí§ÒâÎļþдÈëÎó²î£¨CVE-2025-69194£©£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.8·Ö£¨¸ß£©¡£¡£¡£¡£¸ÃÎó²î¿Éµ¼ÖÂÈ«ÇòÔ¼1500Íǫ̀ÔËÐÐGNU Wget2µÄ×°±¸ÃæÁÙΣº¦¡£¡£¡£¡£°üÀ¨£º


  • LinuxЧÀÍÆ÷£¨Debian/Ubuntu/CentOSµÈÖ÷Á÷¿¯ÐаæÔ¤×°£©
  • DevOps×Ô¶¯»¯Á÷Ë®Ïߣ¨CI/CD¹¤¾ßÁ´ÒÀÀµ£©
  • ÆóÒµÍøÂç×°±¸£¨Â·ÓÉÆ÷/·À»ðǽµÄ¹Ì¼þ¸üÐÂÄ£¿£¿£¿é£©
  • ǶÈëʽ¿ª·¢ÇéÐΣ¨YoctoµÈ¹¹½¨ÏµÍ³£©


ÏÖÔÚ£¬£¬£¬£¬£¬¸ÃÎÊÌâÒÑÔÚGNU Wget2 2.2.1°æ±¾ÖÐÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÏà¹ØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£¡£¡£¡£


Îó²îÐÎò


GNU Wget2ÔÚ´¦Öóͷ£MetalinkÎĵµÊ±·¢Ã÷ÁËÒ»¸öÇå¾²ÎÊÌ⣬£¬£¬£¬£¬¸ÃÓ¦ÓóÌÐòÎÞ·¨×¼È·ÑéÖ¤MetalinkÖÐÌṩµÄÎļþ·¾¶¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÐÐΪ½«ÎļþдÈëϵͳÖеķÇÔ¤ÆÚλÖ㬣¬£¬£¬£¬µ¼ÖÂÊý¾Ýɥʧ£¬£¬£¬£¬£¬»ò½øÒ»²½Ëðº¦Óû§µÄÇéÐΡ£¡£¡£¡£


GNU¹Ù·½ÐÎòΪ£ºA security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user¡¯s environment.


Ó°Ïì¹æÄ£


GNU Wget2 < 2.2.1 


Îó²îÔ­Àí


¸ÃÎó²îÔ´ÓÚWget2¶ÔMetalinkÎĵµµÄ·¾¶Ð£Ñé»úÖÆÈ±ÏÝ¡£¡£¡£¡£µ±´¦Öóͷ£MetalinkÎļþʱ£¬£¬£¬£¬£¬³ÌÐòδ׼ȷÑéÖ¤Îļþ·¾¶ÖеÄÌØÊâ×Ö·û£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâMetalinkÎļþÄÚÈÝʵÏÖÒÔϹ¥»÷£¨ÏêϸӰÏìÈ¡¾öÓÚÔËÐÐWget2µÄÓû§È¨ÏÞ£©£º

  • Ŀ¼´©Ô½£ºÍ»ÆÆÏÂÔØÄ¿Â¼ÏÞÖÆ¡£¡£¡£¡£

  • ÎļþÁýÕÖ£ºÏòí§Òâϵͳ·¾¶Ð´Èë¶ñÒâÄÚÈÝ¡£¡£¡£¡£

  • ȨÏÞÌáÉý£ºÍ¨¹ýÁýÕÖϵͳÉèÖÃÎļþ»ñÈ¡¸ßȨÏÞ¡£¡£¡£¡£


Îó²î¸´ÏÖ


ÑéÖ¤ÇéÐΣºUbuntu22.04 GNU Wget2 1.99.1


ͼƬ1.png

ͼƬ2.png


Çå¾²½¨Òé


    Á¬Ã¦Éý¼¶£º

    • GNU¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾Wget2 2.2.1£¬£¬£¬£¬£¬¿Éͨ¹ý°ü¹ÜÀíÆ÷¸üС£¡£¡£¡£

    ÔÝʱ»º½â²½·¥£º

    • ½ûÓÃMetalink¹¦Ð§£ºwget2 --no-metalink FILE¡£¡£¡£¡£

    • ÏÞÖÆÏÂÔØÂ·¾¶£ºwget2 -P /safe/directory/¡£¡£¡£¡£

    • ÑéÖ¤MetalinkÎļþÍêÕûÐÔ£ºÊ¹ÓÃ--checksum²ÎÊý¡£¡£¡£¡£

    ȨÏÞ¿ØÖÆ£º

    • ÒÔ·ÇÌØÈ¨Óû§Éí·ÝÖ´ÐÐWget2¡£¡£¡£¡£

    • ÉèÖÃSELinux/AppArmorÇ¿ÖÆ»á¼û¿ØÖÆÕ½ÂÔ¡£¡£¡£¡£


    ²Î¿¼Á´½Ó£º

    [1]https://gitlab.com/gnuwget/wget2/-/commit/684be4785280fbe6b8666080bbdd87e7e5299ac5

    [2]https://access.redhat.com/security/cve/cve-2025-69194


    c7c7ÓéÀÖÆ½Ì¨Æð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


    ADLab½¨ÉèÓÚ1999Ä꣬£¬£¬£¬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬£¬£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î7000Óà¸ö£¬£¬£¬£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç»ù´¡Çå¾²Ñо¿¡¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©Çå¾²Ñо¿¡¢Òƶ¯ÖÕ¶ËÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢AIÇå¾²Ñо¿¡¢µÍ¿ÕÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·Àϵͳ½¨Éè¡£¡£¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵È¡£¡£¡£¡£


    adlab.jpg