¡¾¸´ÏÖ¡¿GNU Wget2 Ŀ¼´©Ô½·ì϶£¨CVE-2025-69194£©

°ä²¼¹¦·ò 2026-01-06

GNU Wget2ÊǾ­µäÏÂÔØ¹¤¾ßWgetµÄÏÖ´ú»¯¼ÌÈÎÕß £¬Ëüͨ¹ý¶àÏ̡߳¢HTTP/2Ö§³Ö¼°µÝ¹éÏÂÔØÖ°ÄÜ £¬ÌṩÁ˸ü¸ßЧ¡¢¸ü¼±¾çµÄºÅÁîÐÐÏÂÔØÂÄÀú¡£


MetalinkÊÇÒ»ÖÖ»ùÓÚXMLµÄÔªÊý¾ÝÎļþÌåʽ £¬Ëü½«Ò»¸öÎļþµÄ¶à¸öÏÂÔØ¾µÏñµØÖ·ºÍУÑéÐÅÏ¢ÕûºÏÔÚһ· £¬ÈÃÏÂÔØ¹¤¾ßÄÜʵÏÖ×Ô¶¯·À´í¡¢Ð£ÑéÒÔ¼°¿ç·þÎñÆ÷µÄ·Ö¶Î¼Ó¿ìÏÂÔØ¡£


2025Äê12ÔÂ28ÈÕ £¬GNU°ä²¼Á˸üР£¬½¨¸´ÁËGNU Wget2ÖÐͨ¹ýMetalinkĿ¼´©Ô½½øÐÐËÁÒâÎļþдÈë·ì϶£¨CVE-2025-69194£© £¬CVSSÆÀ·Ö8.8·Ö£¨¸ß£©¡£¸Ã·ì϶¿Éµ¼ÖÂÈ«ÇòÔ¼1500Íǫ̀ÔËÐÐGNU Wget2µÄÉè±¸Ãæ¶Ô·çÏÕ¡£Ô̺¬£º


  • Linux·þÎñÆ÷£¨Debian/Ubuntu/CentOSµÈÖ÷Á÷¿¯ÐаæÔ¤×°£©
  • DevOps×Ô¶¯»¯Á÷Ë®Ïߣ¨CI/CD¹¤¾ßÁ´ÒÀÀµ£©
  • ÆóÒµÍøÂçÉ豸£¨Â·ÓÉÆ÷/·À»ðǽµÄ¹Ì¼þ¸üÐÂÄ£¿é£©
  • ǶÈëʽ¿ª·¢»·¾³£¨YoctoµÈ¹¹½¨ÏµÍ³£©


Ŀǰ £¬¸ÃÎÊÌâÒÑÔÚGNU Wget2 2.2.1°æ±¾Öн¨¸´ £¬½¨ÒéÓйØÓû§ÊµÊ±¸üÐÂÖÁ×îа汾¡£


·ìϼûèÊö


GNU Wget2ÔÚ´¦ÖÃMetalinkÎĵµÊ±·¢ÏÖÁËÒ»¸ö°²È«ÎÊÌâ £¬¸ÃÀûÓ÷¨Ê½ÎÞ·¨ÕýÈ·ÑéÖ¤MetalinkÖÐÌṩµÄÎļþõè¾¶¡£¹¥»÷ÕßÄܹ»ÀûÓôËÐÐΪ½«ÎļþдÈëϵͳÖеķÇÔ¤ÆÚµØÎ» £¬µ¼ÖÂÊý¾ÝÃÔʧ £¬»ò½øÒ»²½ÇÖº¦Óû§µÄ»·¾³¡£


GNU¹Ù·½ÃèÊöΪ£ºA security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user¡¯s environment.


Ó°ÏìÁìÓò


GNU Wget2 < 2.2.1 


·ì϶µÀÀí


¸Ã·ì϶ԴÓÚWget2¶ÔMetalinkÎĵµµÄõ辶УÑé»úÔìȱµã¡£µ±´¦ÖÃMetalinkÎļþʱ £¬·¨Ê½Î´ÕýÈ·ÑéÖ¤Îļþõè¾¶ÖеÄÌØÊâ×Ö·û £¬µ¼Ö¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâMetalinkÎļþÄÚÈÝʵÏÖÒÔϹ¥»÷£¨¾ßÌåÓ°ÏìÈ¡¾öÓÚÔËÐÐWget2µÄÓû§È¨ÏÞ£©£º

  • Ŀ¼´©Ô½£ºÍ»ÆÆÏÂÔØÄ¿Â¼ÏÞ¶È¡£

  • Îļþ¸²¸Ç£ºÏòËÁÒâϵͳõ辶дÈë¶ñÒâÄÚÈÝ¡£

  • ȨÏÞÌáÉý£ºÍ¨¹ý¸²¸ÇϵͳÅäÖÃÎļþ»ñÈ¡¸ßȨÏÞ¡£


·ì϶¸´ÏÖ


ÑéÖ¤»·¾³£ºUbuntu22.04 GNU Wget2 1.99.1


ͼƬ1.png

ͼƬ2.png


°²È«½¨Òé


    µ±¼´Éý¼¶£º

    • GNU¹Ù·½ÒѰ䲼½¨¸´°æ±¾Wget2 2.2.1 £¬¿Éͨ¹ý°üÖÎÀíÆ÷¸üС£

    һʱ»º½â´ëÊ©£º

    • ½ûÓÃMetalinkÖ°ÄÜ£ºwget2 --no-metalink FILE¡£

    • ÏÞ¶ÈÏÂÔØõè¾¶£ºwget2 -P /safe/directory/¡£

    • ÑéÖ¤MetalinkÎļþÆëÈ«ÐÔ£ºÊ¹ÓÃ--checksum²ÎÊý¡£

    ȨÏÞ½ÚÔ죺

    • ÒÔ·ÇÌØÈ¨Óû§Éí·ÝÖ´ÐÐWget2¡£

    • ÅäÖÃSELinux/AppArmorÇ¿Ôì½Ó¼û½ÚÔìÕ½Êõ¡£


    ²Î¿¼Á´½Ó£º

    [1]https://gitlab.com/gnuwget/wget2/-/commit/684be4785280fbe6b8666080bbdd87e7e5299ac5

    [2]https://access.redhat.com/security/cve/cve-2025-69194


    GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


    ADLab³ÉÁ¢ÓÚ1999Äê £¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò» £¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖÁĿǰ £¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö £¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑÓ×¢ÔËÓªÉÌ»ù´¡ÍøÂçÉèÊ©°²È«×êÑÓ×¢ÒÆ¶¯Öն˰²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×¢ÐÅ´´°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢³µÁªÍø°²È«×êÑÓ×¢¹¤¿Ø°²È«×êÑÓ×¢ÎÞÏß°²È«×êÑÓ×¢Êý¾Ý°²È«×êÑÓ×¢AI°²È«×êÑÓ×¢µÍ¿Õ°²È«×êÑÓ×¢¸ß¼¶Íþв×êÑÓ×¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£


    adlab.jpg