¡¾¸´ÏÖ¡¿GNU Wget2 Ŀ¼´©Ô½Îó²î£¨CVE-2025-69194£©
Ðû²¼Ê±¼ä 2026-01-06GNU Wget2ÊǾµäÏÂÔØ¹¤¾ßWgetµÄÏÖ´ú»¯¼ÌÈÎÕߣ¬Ëüͨ¹ý¶àÏ̡߳¢HTTP/2Ö§³Ö¼°µÝ¹éÏÂÔØ¹¦Ð§£¬ÌṩÁ˸ü¸ßЧ¡¢¸ü¿ìËÙµÄÏÂÁîÐÐÏÂÔØÌåÑé¡£
MetalinkÊÇÒ»ÖÖ»ùÓÚXMLµÄÔªÊý¾ÝÎļþÃûÌã¬Ëü½«Ò»¸öÎļþµÄ¶à¸öÏÂÔØ¾µÏñµØµãºÍУÑéÐÅÏ¢ÕûºÏÔÚÒ»Æð£¬ÈÃÏÂÔØ¹¤¾ßÄÜʵÏÖ×Ô¶¯·À´í¡¢Ð£ÑéÒÔ¼°¿ç·þÎñÆ÷µÄ·Ö¶Î¼ÓËÙÏÂÔØ¡£
2025Äê12ÔÂ28ÈÕ£¬GNUÐû²¼Á˸üУ¬ÐÞ¸´ÁËGNU Wget2ÖÐͨ¹ýMetalinkĿ¼´©Ô½¾ÙÐÐí§ÒâÎļþдÈëÎó²î£¨CVE-2025-69194£©£¬CVSSÆÀ·Ö8.8·Ö£¨¸ß£©¡£¸ÃÎó²î¿Éµ¼ÖÂÈ«ÇòÔ¼1500Íǫ̀ÔËÐÐGNU Wget2µÄ×°±¸ÃæÁÙΣº¦¡£°üÀ¨£º
Linux·þÎñÆ÷£¨Debian/Ubuntu/CentOSµÈÖ÷Á÷¿¯ÐаæÔ¤×°£© DevOps×Ô¶¯»¯Á÷Ë®Ïߣ¨CI/CD¹¤¾ßÁ´ÒÀÀµ£© ÆóÒµÍøÂç×°±¸£¨Â·ÓÉÆ÷/·À»ðǽµÄ¹Ì¼þ¸üÐÂÄ£¿é£© ǶÈëʽ¿ª·¢ÇéÐΣ¨YoctoµÈ¹¹½¨ÏµÍ³£©
ÏÖÔÚ£¬¸ÃÎÊÌâÒÑÔÚGNU Wget2 2.2.1°æ±¾ÖÐÐÞ¸´£¬½¨ÒéÏà¹ØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£
Îó²îÐÎò
GNU Wget2ÔÚ´¦Öóͷ£MetalinkÎĵµÊ±·¢Ã÷ÁËÒ»¸öÇå¾²ÎÊÌ⣬¸ÃÓ¦ÓóÌÐòÎÞ·¨×¼È·ÑéÖ¤MetalinkÖÐÌṩµÄÎļþ·¾¶¡£¹¥»÷Õß¿ÉÒÔʹÓôËÐÐΪ½«ÎļþдÈëϵͳÖеķÇÔ¤ÆÚλÖ㬵¼ÖÂÊý¾Ýɥʧ£¬»ò½øÒ»²½Ëðº¦Óû§µÄÇéÐΡ£
GNU¹Ù·½ÐÎòΪ£ºA security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user¡¯s environment.
Ó°Ïì¹æÄ£
GNU Wget2 < 2.2.1
Îó²îÔÀí
¸ÃÎó²îÔ´ÓÚWget2¶ÔMetalinkÎĵµµÄ·¾¶Ð£Ñé»úÖÆÈ±ÏÝ¡£µ±´¦Öóͷ£MetalinkÎļþʱ£¬³ÌÐòδ׼ȷÑéÖ¤Îļþ·¾¶ÖеÄÌØÊâ×Ö·û£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâMetalinkÎļþÄÚÈÝʵÏÖÒÔϹ¥»÷£¨ÏêϸӰÏìÈ¡¾öÓÚÔËÐÐWget2µÄÓû§È¨ÏÞ£©£º
Ŀ¼´©Ô½£ºÍ»ÆÆÏÂÔØÄ¿Â¼ÏÞÖÆ¡£
ÎļþÁýÕÖ£ºÏòí§Òâϵͳ·¾¶Ð´Èë¶ñÒâÄÚÈÝ¡£
ȨÏÞÌáÉý£ºÍ¨¹ýÁýÕÖϵͳÉèÖÃÎļþ»ñÈ¡¸ßȨÏÞ¡£
Îó²î¸´ÏÖ
ÑéÖ¤ÇéÐΣºUbuntu22.04 GNU Wget2 1.99.1


Çå¾²½¨Òé
Á¬Ã¦Éý¼¶£º
GNU¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾Wget2 2.2.1£¬¿Éͨ¹ý°ü¹ÜÀíÆ÷¸üС£
ÔÝʱ»º½â²½·¥£º
½ûÓÃMetalink¹¦Ð§£ºwget2 --no-metalink FILE¡£
ÏÞÖÆÏÂÔØÂ·¾¶£ºwget2 -P /safe/directory/¡£
ÑéÖ¤MetalinkÎļþÍêÕûÐÔ£ºÊ¹ÓÃ--checksum²ÎÊý¡£
ȨÏÞ¿ØÖÆ£º
ÒÔ·ÇÌØÈ¨Óû§Éí·ÝÖ´ÐÐWget2¡£
ÉèÖÃSELinux/AppArmorÇ¿ÖÆ»á¼û¿ØÖÆÕ½ÂÔ¡£
[1]https://gitlab.com/gnuwget/wget2/-/commit/684be4785280fbe6b8666080bbdd87e7e5299ac5
[2]https://access.redhat.com/security/cve/cve-2025-69194
×ðÁú¿Ê±Æð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î7000Óà¸ö£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç»ù´¡Çå¾²Ñо¿¡¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©Çå¾²Ñо¿¡¢Òƶ¯ÖÕ¶ËÇå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢AIÇå¾²Ñо¿¡¢µÍ¿ÕÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·Àϵͳ½¨Éè¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£



¾©¹«Íø°²±¸11010802024551ºÅ