Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-5299

Опубликовано: 13 авг. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-5299: wget security update (MODERATE)

[1.19.5-12.0.1]

  • SSLv3 support dropped from openssl, v3 test certificates need to be replaced [Orabug: 29613455]

[1.19.5-12]

  • Resolves: RHEL-43559 - Misinterpretation of input may lead to improper behavior

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

wget

1.19.5-12.0.1.el8_10

Oracle Linux x86_64

wget

1.19.5-12.0.1.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 5.5
redhat
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
nvd
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
msrc
около 1 года назад

Описание отсутствует

CVSS3: 9.1
debian
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo ...