CVE-2006-6719

Exp

The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command.

Published: 2006-12-23 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2006-6719 is rated High Exploit Risk (65.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 4.48%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2006-6719

EDB-ID Source Kind Published Link
2947 exploit_db edb 2006-12-18 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2006-6719

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-05 4.83% 4.48% -0.36%
2 2025-09-19 3.72% 4.83% +1.11%
3 2025-08-11 3.72%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2006-6719

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2006-6719

OS Trackers for CVE-2006-6719

vendor priority summary link
alpine CVE-2006-6719: no source package rows; 0 state rows across 0 repos (none); fixed 0, open 0. https://security.alpinelinux.org/vuln/CVE-2006-6719
debian unimportant CVE-2006-6719 unimportant priority: Debian including 1 source packages (wget), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2006-6719
redhat low https://access.redhat.com/security/cve/CVE-2006-6719
suse medium CVE-2006-6719 severity moderate: SUSE including 9 source package names (wget-1.11.4-1.15.1, wget-1.11.4-1.19.1, …), 11 product×package rows across 9 product lines (SUSE Linux Enterprise Server 11 SP1, SUSE Linux Enterprise Server 11 SP2, … (9 product lines)): Fixed 11. https://www.suse.com/security/cve/CVE-2006-6719/
ubuntu low CVE-2006-6719 low priority: Ubuntu including 1 source packages (wget), 4 status rows across 4 suites (precise, trusty, upstream, xenial): not-affected 3, released 1. https://ubuntu.com/security/CVE-2006-6719

Vendor comments (NVD) for CVE-2006-6719

  • Red Hat (2009-10-07T00:00:00)

    Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=221459 We do not consider a crash of a client application such as wget to be a security issue. This flaw was fixed in wget shipped in Red Hat Enterprise Linux 5 before the initial release of the product. Version of wget shipped in Red Hat Enterprise Linux 3 and 4 are affected by this bug.

Affected software / configurations for CVE-2006-6719

Vendor Product Version Raw CPE
gnu wget 1.5.3 cpe:2.3:a:gnu:wget:1.5.3:*:*:*:*:*:*:*
gnu wget 1.6 cpe:2.3:a:gnu:wget:1.6:*:*:*:*:*:*:*
gnu wget 1.7 cpe:2.3:a:gnu:wget:1.7:*:*:*:*:*:*:*
gnu wget 1.7.1 cpe:2.3:a:gnu:wget:1.7.1:*:*:*:*:*:*:*
gnu wget 1.8 cpe:2.3:a:gnu:wget:1.8:*:*:*:*:*:*:*
gnu wget 1.8.1 cpe:2.3:a:gnu:wget:1.8.1:*:*:*:*:*:*:*
gnu wget 1.8.2 cpe:2.3:a:gnu:wget:1.8.2:*:*:*:*:*:*:*
gnu wget 1.9 cpe:2.3:a:gnu:wget:1.9:*:*:*:*:*:*:*
gnu wget 1.9.1 cpe:2.3:a:gnu:wget:1.9.1:*:*:*:*:*:*:*
gnu wget 1.10 cpe:2.3:a:gnu:wget:1.10:*:*:*:*:*:*:*
gnu wget 1.10.1 cpe:2.3:a:gnu:wget:1.10.1:*:*:*:*:*:*:*
gnu wget 1.10.2 cpe:2.3:a:gnu:wget:1.10.2:*:*:*:*:*:*:*

References for CVE-2006-6719

cvelogic Threat Intelligence