Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58470

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

An integer overflow in GNU Wget's parse_content_range() function allows malicious servers to send crafted Content-Range headers. This triggers undefined behavior and download desynchronization, potentially causing a denial of service or data integrity issues for the client.

Отчет

Moderate: GNU Wget is vulnerable to a client-side integer overflow in its Content-Range header processing. If a client connects to an attacker-controlled server, the server can return anomalous headers that cause undefined behavior and stream desynchronization. This results in local data integrity issues or a denial of service, though the impact is strictly limited to the Wget process itself.

Меры по смягчению последствий

To mitigate this issue, users should avoid using wget to download content from untrusted or unverified sources. When wget is used in automated scripts or environments, ensure that the target servers are trusted to prevent exposure to malicious Content-Range headers. Restricting network access for wget to only trusted hosts can also reduce the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wgetFix deferred
Red Hat Enterprise Linux 6wgetOut of support scope
Red Hat Enterprise Linux 7wgetOut of support scope
Red Hat Enterprise Linux 8wgetFix deferred
Red Hat Enterprise Linux 9wgetFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2497860wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
27 дней назад

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

CVSS3: 5.3
nvd
27 дней назад

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

CVSS3: 5.3
debian
27 дней назад

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer ...

CVSS3: 5.3
github
27 дней назад

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

suse-cvrf
12 дней назад

Security update for wget

5.3 Medium

CVSS3