GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource (CVE-2016-4971).
Fixed a potential race condition by creating files with .tmp ext and making them accessible to the current user only (CVE-2016-7098).