Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38428

Опубликовано: 01 июн. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

A flaw was found in wget. Incorrect handling of semicolons in the userinfo subcomponent of a URI allows it to be misinterpreted as part of the host subcomponent, potentially exposing user credentials.

Отчет

Only calls to Wget using semicolons in the userinfo subcomponent of a URI are vulnerable to this issue. However, this is allowed by the standard and is supported by other similar tools. To exploit this issue, an attacker must convince a local user into running Wget with a specially crafted userinfo subcomponent, limiting the exposure of this vulnerability. For these reasons, this vulnerability has been rated with a moderate severity. Additionally, this vulnerability only affects wget 1.x, wget2 is not affected.

Меры по смягчению последствий

Make sure to not add semicolons in the userinfo subcomponent of a URI.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wget2Not affected
Red Hat Enterprise Linux 6wgetOut of support scope
Red Hat Enterprise Linux 7wgetOut of support scope
Red Hat Enterprise Linux 8wgetFixedRHSA-2024:529913.08.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportwgetFixedRHSA-2024:499806.08.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicewgetFixedRHSA-2024:499806.08.2024
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionswgetFixedRHSA-2024:499806.08.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportwgetFixedRHSA-2024:620803.09.2024
Red Hat Enterprise Linux 9wgetFixedRHSA-2024:619203.09.2024
Red Hat Enterprise Linux 9.2 Extended Update SupportwgetFixedRHSA-2024:643805.09.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-115
https://bugzilla.redhat.com/show_bug.cgi?id=2292836wget: Misinterpretation of input may lead to improper behavior

EPSS

Процентиль: 42%
0.00197
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
почти 2 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
nvd
почти 2 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
msrc
около 1 месяца назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
debian
почти 2 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo ...

suse-cvrf
почти 2 года назад

Security update for wget

EPSS

Процентиль: 42%
0.00197
Низкий

5.5 Medium

CVSS3