Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-38428

Опубликовано: 16 июн. 2024
Источник: debian
EPSS Низкий

Описание

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wgetfixed1.24.5-2package
wgetfixed1.21.3-1+deb12u1bookwormpackage
wgetpostponedbusterpackage

Примечания

  • https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html

  • Fixed by: https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace

EPSS

Процентиль: 50%
0.00265
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 5.5
redhat
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
nvd
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
msrc
12 месяцев назад

Описание отсутствует

suse-cvrf
12 месяцев назад

Security update for wget

EPSS

Процентиль: 50%
0.00265
Низкий