Описание
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the html_quote_string() function by providing a specially crafted HTML attribute. This can lead to memory corruption and potentially result in arbitrary code execution or a denial of service.
Отчет
This Moderate impact heap buffer overflow in GNU Wget occurs when processing HTML attributes with extensive entity encoding. Successful exploitation requires user interaction, as a victim must download a specially crafted HTML file, and is further constrained by high attack complexity. This limits the direct risk to Red Hat systems where Wget is typically used for trusted content retrieval.
Меры по смягчению последствий
Users are advised to avoid retrieving content from untrusted or unverified sources using Wget.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | wget | Affected | ||
| Red Hat Enterprise Linux 6 | wget | Affected | ||
| Red Hat Enterprise Linux 7 | wget | Affected | ||
| Red Hat Enterprise Linux 8 | wget | Affected | ||
| Red Hat Enterprise Linux 9 | wget | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buff ...
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
EPSS
5.9 Medium
CVSS3