A vulnerability allowing arbitrary file overwriting has been eliminated in GNU Wget2 2.2.1.

The release of GNU Wget2 version 2.2.1 is available, which develops a completely rewritten and revamped version of the program for automating recursive content downloads. Wget2 offers a set of additional options, supports multi-threaded downloads, allows access to functionality through the libwget library, supports HTTP/2 and TLS 1.3 protocols, enables downloading only changed data, can save data from streaming servers, properly handles internationalized domain names, and can re-encode downloaded content. The wget2 utility is provided under the GPLv3+ license, while the library is under the LGPLv3+.

The new version addresses two vulnerabilities:

  • CVE-2025-69194 — Insufficient path validation when processing Metalink format content, which is used to describe links to files for download. By using the sequence "..\/" in file paths within the block, an attacker can create, delete, or overwrite arbitrary files outside the base directory where downloads occur. For example, an attacker could overwrite the contents of ~/ .ssh/authorized_keys or ~/ .bashrc to execute their code in the system.
  • CVE-2025-69195 — Buffer overflow in the file name cleanup code in the get_local_filename_real() function, potentially leading to code execution when processing specially crafted URLs on download pages or when handling redirects. The issue occurs when the "—restrict-file-names=windows|unix|ascii" option is enabled and is caused by allocating a fixed 1024-byte buffer without checking the actual size of the data being written.

Among the non-security-related changes, the addition of the "—show-progress" option for indicating download progress, the use of local time when specifying the "—no-use-server-timestamps" option, support for the 'no_' prefix in configuration parameters, and the involvement of libnghttp2 for testing HTTP/2 can be noted.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster