¡¾¸´ÏÖ¡¿GNU Wget2 Ŀ¼´©Ô½·ì϶£¨CVE-2025-69194£©
°ä²¼¹¦·ò 2026-01-06GNU Wget2ÊǾµäÏÂÔØ¹¤¾ßWgetµÄÏÖ´ú»¯¼ÌÈÎÕߣ¬Ëüͨ¹ý¶àÏ̡߳¢¡¢¡¢HTTP/2Ö§³Ö¼°µÝ¹éÏÂÔØÖ°ÄÜ£¬ÌṩÁ˸ü¸ßЧ¡¢¡¢¡¢¸ü¼±¾çµÄºÅÁîÐÐÏÂÔØÂÄÀú¡£
MetalinkÊÇÒ»ÖÖ»ùÓÚXMLµÄÔªÊý¾ÝÎļþÌåʽ£¬Ëü½«Ò»¸öÎļþµÄ¶à¸öÏÂÔØ¾µÏñµØÖ·ºÍУÑéÐÅÏ¢ÕûºÏÔÚһ·£¬ÈÃÏÂÔØ¹¤¾ßÄÜʵÏÖ×Ô¶¯·À´í¡¢¡¢¡¢Ð£ÑéÒÔ¼°¿ç·þÎñÆ÷µÄ·Ö¶Î¼Ó¿ìÏÂÔØ¡£
2025Äê12ÔÂ28ÈÕ£¬GNU°ä²¼Á˸üУ¬ÐÞ¸´ÁËGNU Wget2ÖÐͨ¹ýMetalinkĿ¼´©Ô½½øÐÐËÁÒâÎļþдÈë·ì϶£¨CVE-2025-69194£©£¬CVSSÆÀ·Ö8.8·Ö£¨¸ß£©¡£¸Ã·ì϶¿Éµ¼ÖÂÈ«ÇòÔ¼1500Íǫ̀ÔËÐÐGNU Wget2µÄÉè±¸Ãæ¶Ô·çÏÕ¡£Ô̺¬£º
Linux·þÎñÆ÷£¨Debian/Ubuntu/CentOSµÈÖ÷Á÷¿¯ÐаæÔ¤×°£© DevOps×Ô¶¯»¯Á÷Ë®Ïߣ¨CI/CD¹¤¾ßÁ´ÒÀÀµ£© ÆóÒµÍøÂçÉ豸£¨Â·ÓÉÆ÷/·À»ðǽµÄ¹Ì¼þ¸üÐÂÄ£¿é£© ǶÈëʽ¿ª·¢»·¾³£¨YoctoµÈ¹¹½¨ÏµÍ³£©
Ŀǰ£¬¸ÃÎÊÌâÒÑÔÚGNU Wget2 2.2.1°æ±¾ÖÐÐÞ¸´£¬½¨ÒéÓйØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£
·ì϶ÃèÊö
GNU Wget2ÔÚ´¦ÖÃMetalinkÎĵµÊ±·¢ÏÖÁËÒ»¸ö°²È«ÎÊÌ⣬¸ÃÀûÓ÷¨Ê½ÎÞ·¨ÕýÈ·ÑéÖ¤MetalinkÖÐÌṩµÄÎļþõè¾¶¡£¹¥»÷ÕßÄܹ»ÀûÓôËÐÐΪ½«ÎļþдÈëϵͳÖеķÇÔ¤ÆÚµØÎ»£¬µ¼ÖÂÊý¾ÝÃÔʧ£¬»ò½øÒ»²½ÇÖº¦Óû§µÄ»·¾³¡£
GNU¹Ù·½ÃèÊöΪ£ºA security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user¡¯s environment.
Ó°ÏìÁìÓò
GNU Wget2 < 2.2.1
·ì϶µÀÀí
¸Ã·ì϶ԴÓÚWget2¶ÔMetalinkÎĵµµÄõ辶УÑé»úÖÆÈ±µã¡£µ±´¦ÖÃMetalinkÎļþʱ£¬·¨Ê½Î´ÕýÈ·ÑéÖ¤Îļþõè¾¶ÖеÄÌØÊâ×Ö·û£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâMetalinkÎļþÄÚÈÝʵÏÖÒÔϹ¥»÷£¨¾ßÌåÓ°ÏìÈ¡¾öÓÚÔËÐÐWget2µÄÓû§È¨ÏÞ£©£º
Ŀ¼´©Ô½£ºÍ»ÆÆÏÂÔØÄ¿Â¼ÏÞ¶È¡£
Îļþ¸²¸Ç£ºÏòËÁÒâϵͳõ辶дÈë¶ñÒâÄÚÈÝ¡£
ȨÏÞÌáÉý£ºÍ¨¹ý¸²¸ÇϵͳÅäÖÃÎļþ»ñÈ¡¸ßȨÏÞ¡£
·ì϶¸´ÏÖ
ÑéÖ¤»·¾³£ºUbuntu22.04 GNU Wget2 1.99.1


°²È«½¨Òé
Á¢¼´Éý¼¶£º
GNU¹Ù·½ÒѰ䲼ÐÞ¸´°æ±¾Wget2 2.2.1£¬¿Éͨ¹ý°üÖÎÀíÆ÷¸üС£
һʱ»º½â´ëÊ©£º
½ûÓÃMetalinkÖ°ÄÜ£ºwget2 --no-metalink FILE¡£
ÏÞ¶ÈÏÂÔØõè¾¶£ºwget2 -P /safe/directory/¡£
ÑéÖ¤MetalinkÎļþÆëÈ«ÐÔ£ºÊ¹ÓÃ--checksum²ÎÊý¡£
ȨÏÞ½ÚÖÆ£º
ÒÔ·ÇÌØÈ¨Óû§Éí·ÝÖ´ÐÐWget2¡£
ÅäÖÃSELinux/AppArmorÇ¿ÖÆ½Ó¼û½ÚÖÆÕ½Êõ¡£
[1]https://gitlab.com/gnuwget/wget2/-/commit/684be4785280fbe6b8666080bbdd87e7e5299ac5
[2]https://access.redhat.com/security/cve/cve-2025-69194
OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£½ØÖÁĿǰ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç»ù´¡°²È«×êÑС¢¡¢¡¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©°²È«×êÑС¢¡¢¡¢Òƶ¯Öն˰²È«×êÑС¢¡¢¡¢Ôư²È«×êÑС¢¡¢¡¢ÐÅ´´°²È«×êÑС¢¡¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢¡¢³µÁªÍø°²È«×êÑС¢¡¢¡¢¹¤¿Ø°²È«×êÑС¢¡¢¡¢ÎÞÏß°²È«×êÑС¢¡¢¡¢Êý¾Ý°²È«×êÑС¢¡¢¡¢AI°²È«×êÑС¢¡¢¡¢µÍ¿Õ°²È«×êÑС¢¡¢¡¢¸ß¼¶Íþв×êÑС¢¡¢¡¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£



¾©¹«Íø°²±¸11010802024551ºÅ