Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58472

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the html_quote_string() function by providing a specially crafted HTML attribute. This can lead to memory corruption and potentially result in arbitrary code execution or a denial of service.

Отчет

This Moderate impact heap buffer overflow in GNU Wget occurs when processing HTML attributes with extensive entity encoding. Successful exploitation requires user interaction, as a victim must download a specially crafted HTML file, and is further constrained by high attack complexity. This limits the direct risk to Red Hat systems where Wget is typically used for trusted content retrieval.

Меры по смягчению последствий

Users are advised to avoid retrieving content from untrusted or unverified sources using Wget.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wgetAffected
Red Hat Enterprise Linux 6wgetAffected
Red Hat Enterprise Linux 7wgetAffected
Red Hat Enterprise Linux 8wgetAffected
Red Hat Enterprise Linux 9wgetAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2497857wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute

EPSS

Процентиль: 13%
0.00221
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVSS3: 5.9
nvd
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVSS3: 5.9
debian
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buff ...

CVSS3: 5.9
github
27 дней назад

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

suse-cvrf
12 дней назад

Security update for wget

EPSS

Процентиль: 13%
0.00221
Низкий

5.9 Medium

CVSS3