Описание
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
A flaw was found in wget. Incorrect handling of semicolons in the userinfo subcomponent of a URI allows it to be misinterpreted as part of the host subcomponent, potentially exposing user credentials.
Отчет
Only calls to Wget using semicolons in the userinfo subcomponent of a URI are vulnerable to this issue. However, this is allowed by the standard and is supported by other similar tools. To exploit this issue, an attacker must convince a local user into running Wget with a specially crafted userinfo subcomponent, limiting the exposure of this vulnerability. For these reasons, this vulnerability has been rated with a moderate severity. Additionally, this vulnerability only affects wget 1.x, wget2 is not affected.
Меры по смягчению последствий
Make sure to not add semicolons in the userinfo subcomponent of a URI.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wget2 | Not affected | ||
| Red Hat Enterprise Linux 6 | wget | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wget | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wget | Fixed | RHSA-2024:5299 | 13.08.2024 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | wget | Fixed | RHSA-2024:4998 | 06.08.2024 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | wget | Fixed | RHSA-2024:4998 | 06.08.2024 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | wget | Fixed | RHSA-2024:4998 | 06.08.2024 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | wget | Fixed | RHSA-2024:6208 | 03.09.2024 |
| Red Hat Enterprise Linux 9 | wget | Fixed | RHSA-2024:6192 | 03.09.2024 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | wget | Fixed | RHSA-2024:6438 | 05.09.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo ...
EPSS
5.5 Medium
CVSS3