¡¾¸´ÏÖ¡¿GNU Wget2 Ŀ¼´©Ô½·ì϶£¨CVE-2025-69194£©

°ä²¼¹¦·ò 2026-01-06

GNU Wget2ÊǾ­µäÏÂÔØ¹¤¾ßWgetµÄÏÖ´ú»¯¼ÌÈÎÕߣ¬Ëüͨ¹ý¶àÏ̡߳¢¡¢¡¢HTTP/2Ö§³Ö¼°µÝ¹éÏÂÔØÖ°ÄÜ£¬ÌṩÁ˸ü¸ßЧ¡¢¡¢¡¢¸ü¼±¾çµÄºÅÁîÐÐÏÂÔØÂÄÀú¡£


MetalinkÊÇÒ»ÖÖ»ùÓÚXMLµÄÔªÊý¾ÝÎļþÌåʽ£¬Ëü½«Ò»¸öÎļþµÄ¶à¸öÏÂÔØ¾µÏñµØÖ·ºÍУÑéÐÅÏ¢ÕûºÏÔÚһ·£¬ÈÃÏÂÔØ¹¤¾ßÄÜʵÏÖ×Ô¶¯·À´í¡¢¡¢¡¢Ð£ÑéÒÔ¼°¿ç·þÎñÆ÷µÄ·Ö¶Î¼Ó¿ìÏÂÔØ¡£


2025Äê12ÔÂ28ÈÕ£¬GNU°ä²¼Á˸üУ¬ÐÞ¸´ÁËGNU Wget2ÖÐͨ¹ýMetalinkĿ¼´©Ô½½øÐÐËÁÒâÎļþдÈë·ì϶£¨CVE-2025-69194£©£¬CVSSÆÀ·Ö8.8·Ö£¨¸ß£©¡£¸Ã·ì϶¿Éµ¼ÖÂÈ«ÇòÔ¼1500Íǫ̀ÔËÐÐGNU Wget2µÄÉè±¸Ãæ¶Ô·çÏÕ¡£Ô̺¬£º


  • Linux·þÎñÆ÷£¨Debian/Ubuntu/CentOSµÈÖ÷Á÷¿¯ÐаæÔ¤×°£©
  • DevOps×Ô¶¯»¯Á÷Ë®Ïߣ¨CI/CD¹¤¾ßÁ´ÒÀÀµ£©
  • ÆóÒµÍøÂçÉ豸£¨Â·ÓÉÆ÷/·À»ðǽµÄ¹Ì¼þ¸üÐÂÄ£¿é£©
  • ǶÈëʽ¿ª·¢»·¾³£¨YoctoµÈ¹¹½¨ÏµÍ³£©


Ŀǰ£¬¸ÃÎÊÌâÒÑÔÚGNU Wget2 2.2.1°æ±¾ÖÐÐÞ¸´£¬½¨ÒéÓйØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£


·ì϶ÃèÊö


GNU Wget2ÔÚ´¦ÖÃMetalinkÎĵµÊ±·¢ÏÖÁËÒ»¸ö°²È«ÎÊÌ⣬¸ÃÀûÓ÷¨Ê½ÎÞ·¨ÕýÈ·ÑéÖ¤MetalinkÖÐÌṩµÄÎļþõè¾¶¡£¹¥»÷ÕßÄܹ»ÀûÓôËÐÐΪ½«ÎļþдÈëϵͳÖеķÇÔ¤ÆÚµØÎ»£¬µ¼ÖÂÊý¾ÝÃÔʧ£¬»ò½øÒ»²½ÇÖº¦Óû§µÄ»·¾³¡£


GNU¹Ù·½ÃèÊöΪ£ºA security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user¡¯s environment.


Ó°ÏìÁìÓò


GNU Wget2 < 2.2.1 


·ì϶µÀÀí


¸Ã·ì϶ԴÓÚWget2¶ÔMetalinkÎĵµµÄõ辶УÑé»úÖÆÈ±µã¡£µ±´¦ÖÃMetalinkÎļþʱ£¬·¨Ê½Î´ÕýÈ·ÑéÖ¤Îļþõè¾¶ÖеÄÌØÊâ×Ö·û£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâMetalinkÎļþÄÚÈÝʵÏÖÒÔϹ¥»÷£¨¾ßÌåÓ°ÏìÈ¡¾öÓÚÔËÐÐWget2µÄÓû§È¨ÏÞ£©£º

  • Ŀ¼´©Ô½£ºÍ»ÆÆÏÂÔØÄ¿Â¼ÏÞ¶È¡£

  • Îļþ¸²¸Ç£ºÏòËÁÒâϵͳõ辶дÈë¶ñÒâÄÚÈÝ¡£

  • ȨÏÞÌáÉý£ºÍ¨¹ý¸²¸ÇϵͳÅäÖÃÎļþ»ñÈ¡¸ßȨÏÞ¡£


·ì϶¸´ÏÖ


ÑéÖ¤»·¾³£ºUbuntu22.04 GNU Wget2 1.99.1


ͼƬ1.png

ͼƬ2.png


°²È«½¨Òé


    Á¢¼´Éý¼¶£º

    • GNU¹Ù·½ÒѰ䲼ÐÞ¸´°æ±¾Wget2 2.2.1£¬¿Éͨ¹ý°üÖÎÀíÆ÷¸üС£

    һʱ»º½â´ëÊ©£º

    • ½ûÓÃMetalinkÖ°ÄÜ£ºwget2 --no-metalink FILE¡£

    • ÏÞ¶ÈÏÂÔØõè¾¶£ºwget2 -P /safe/directory/¡£

    • ÑéÖ¤MetalinkÎļþÆëÈ«ÐÔ£ºÊ¹ÓÃ--checksum²ÎÊý¡£

    ȨÏÞ½ÚÖÆ£º

    • ÒÔ·ÇÌØÈ¨Óû§Éí·ÝÖ´ÐÐWget2¡£

    • ÅäÖÃSELinux/AppArmorÇ¿ÖÆ½Ó¼û½ÚÖÆÕ½Êõ¡£


    ²Î¿¼Á´½Ó£º

    [1]https://gitlab.com/gnuwget/wget2/-/commit/684be4785280fbe6b8666080bbdd87e7e5299ac5

    [2]https://access.redhat.com/security/cve/cve-2025-69194


    OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


    ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£½ØÖÁĿǰ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑС¢¡¢¡¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©°²È«×êÑС¢¡¢¡¢Òƶ¯Öն˰²È«×êÑС¢¡¢¡¢Ôư²È«×êÑС¢¡¢¡¢ÐÅ´´°²È«×êÑС¢¡¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢¡¢³µÁªÍø°²È«×êÑС¢¡¢¡¢¹¤¿Ø°²È«×êÑС¢¡¢¡¢ÎÞÏß°²È«×êÑС¢¡¢¡¢Êý¾Ý°²È«×êÑС¢¡¢¡¢AI°²È«×êÑС¢¡¢¡¢µÍ¿Õ°²È«×êÑС¢¡¢¡¢¸ß¼¶Íþв×êÑС¢¡¢¡¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£


    adlab.jpg