¡¾¸´ÏÖ¡¿GNU Wget2 Ŀ¼´©Ô½·ì϶£¨CVE-2025-69194£©
°ä²¼¹¦·ò 2026-01-06GNU Wget2ÊǾµäÏÂÔØ¹¤¾ßWgetµÄÏÖ´ú»¯¼ÌÈÎÕߣ¬Ëüͨ¹ý¶àÏ̡߳¢HTTP/2Ö§³Ö¼°µÝ¹éÏÂÔØÖ°ÄÜ£¬ÌṩÁ˸ü¸ßЧ¡¢¸ü¼±¾çµÄºÅÁîÐÐÏÂÔØÂÄÀú¡£
MetalinkÊÇÒ»ÖÖ»ùÓÚXMLµÄÔªÊý¾ÝÎļþÌåʽ£¬Ëü½«Ò»¸öÎļþµÄ¶à¸öÏÂÔØ¾µÏñµØÖ·ºÍУÑéÐÅÏ¢ÕûºÏÔÚһ·£¬ÈÃÏÂÔØ¹¤¾ßÄÜʵÏÖ×Ô¶¯·À´í¡¢Ð£ÑéÒÔ¼°¿ç·þÎñÆ÷µÄ·Ö¶Î¼Ó¿ìÏÂÔØ¡£
2025Äê12ÔÂ28ÈÕ£¬GNU°ä²¼Á˸üУ¬½¨¸´ÁËGNU Wget2ÖÐͨ¹ýMetalinkĿ¼´©Ô½½øÐÐËÁÒâÎļþдÈë·ì϶£¨CVE-2025-69194£©£¬CVSSÆÀ·Ö8.8·Ö£¨¸ß£©¡£¸Ã·ì϶¿Éµ¼ÖÂÈ«ÇòÔ¼1500Íǫ̀ÔËÐÐGNU Wget2µÄÉè±¸Ãæ¶Ô·çÏÕ¡£Ô̺¬£º
Linux·þÎñÆ÷£¨Debian/Ubuntu/CentOSµÈÖ÷Á÷¿¯ÐаæÔ¤×°£© DevOps×Ô¶¯»¯Á÷Ë®Ïߣ¨CI/CD¹¤¾ßÁ´ÒÀÀµ£© ÆóÒµÍøÂçÉ豸£¨Â·ÓÉÆ÷/·À»ðǽµÄ¹Ì¼þ¸üÐÂÄ£¿é£© ǶÈëʽ¿ª·¢»·¾³£¨YoctoµÈ¹¹½¨ÏµÍ³£©
Ŀǰ£¬¸ÃÎÊÌâÒÑÔÚGNU Wget2 2.2.1°æ±¾Öн¨¸´£¬½¨ÒéÓйØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£
·ìϼûèÊö
GNU Wget2ÔÚ´¦ÖÃMetalinkÎĵµÊ±·¢ÏÖÁËÒ»¸ö°²È«ÎÊÌ⣬¸ÃÀûÓ÷¨Ê½ÎÞ·¨ÕýÈ·ÑéÖ¤MetalinkÖÐÌṩµÄÎļþõè¾¶¡£¹¥»÷ÕßÄܹ»ÀûÓôËÐÐΪ½«ÎļþдÈëϵͳÖеķÇÔ¤ÆÚµØÎ»£¬µ¼ÖÂÊý¾ÝÃÔʧ£¬»ò½øÒ»²½ÇÖº¦Óû§µÄ»·¾³¡£
GNU¹Ù·½ÃèÊöΪ£ºA security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user¡¯s environment.
Ó°ÏìÁìÓò
GNU Wget2 < 2.2.1
·ì϶µÀÀí
¸Ã·ì϶ԴÓÚWget2¶ÔMetalinkÎĵµµÄõ辶УÑé»úÔìȱµã¡£µ±´¦ÖÃMetalinkÎļþʱ£¬·¨Ê½Î´ÕýÈ·ÑéÖ¤Îļþõè¾¶ÖеÄÌØÊâ×Ö·û£¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâMetalinkÎļþÄÚÈÝʵÏÖÒÔϹ¥»÷£¨¾ßÌåÓ°ÏìÈ¡¾öÓÚÔËÐÐWget2µÄÓû§È¨ÏÞ£©£º
Ŀ¼´©Ô½£ºÍ»ÆÆÏÂÔØÄ¿Â¼ÏÞ¶È¡£
Îļþ¸²¸Ç£ºÏòËÁÒâϵͳõ辶дÈë¶ñÒâÄÚÈÝ¡£
ȨÏÞÌáÉý£ºÍ¨¹ý¸²¸ÇϵͳÅäÖÃÎļþ»ñÈ¡¸ßȨÏÞ¡£
·ì϶¸´ÏÖ
ÑéÖ¤»·¾³£ºUbuntu22.04 GNU Wget2 1.99.1


°²È«½¨Òé
µ±¼´Éý¼¶£º
GNU¹Ù·½ÒѰ䲼½¨¸´°æ±¾Wget2 2.2.1£¬¿Éͨ¹ý°üÖÎÀíÆ÷¸üС£
һʱ»º½â´ëÊ©£º
½ûÓÃMetalinkÖ°ÄÜ£ºwget2 --no-metalink FILE¡£
ÏÞ¶ÈÏÂÔØõè¾¶£ºwget2 -P /safe/directory/¡£
ÑéÖ¤MetalinkÎļþÆëÈ«ÐÔ£ºÊ¹ÓÃ--checksum²ÎÊý¡£
ȨÏÞ½ÚÔ죺
ÒÔ·ÇÌØÈ¨Óû§Éí·ÝÖ´ÐÐWget2¡£
ÅäÖÃSELinux/AppArmorÇ¿Ôì½Ó¼û½ÚÔìÕ½Êõ¡£
[1]https://gitlab.com/gnuwget/wget2/-/commit/684be4785280fbe6b8666080bbdd87e7e5299ac5
[2]https://access.redhat.com/security/cve/cve-2025-69194
GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖÁĿǰ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç»ù´¡°²È«×êÑÓ×¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©°²È«×êÑÓ×¢ÒÆ¶¯Öն˰²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×¢ÐÅ´´°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢³µÁªÍø°²È«×êÑÓ×¢¹¤¿Ø°²È«×êÑÓ×¢ÎÞÏß°²È«×êÑÓ×¢Êý¾Ý°²È«×êÑÓ×¢AI°²È«×êÑÓ×¢µÍ¿Õ°²È«×êÑÓ×¢¸ß¼¶Íþв×êÑÓ×¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£



¾©¹«Íø°²±¸11010802024551ºÅ