Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:01921-1

Опубликовано: 12 июн. 2025
Источник: suse-cvrf

Описание

Security update for wget

This update for wget fixes the following issues:

  • CVE-2024-10524: Dropped support for shorthand URLs that enabled SSRF attacks (bsc#1233773).

Список пакетов

Image SLES12-SP5-Azure-BYOS
wget-1.14-21.25.1
Image SLES12-SP5-Azure-HPC-BYOS
wget-1.14-21.25.1
Image SLES12-SP5-Azure-HPC-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-Azure-SAP-BYOS
wget-1.14-21.25.1
Image SLES12-SP5-Azure-SAP-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-Azure-Standard-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-EC2-BYOS
wget-1.14-21.25.1
Image SLES12-SP5-EC2-ECS-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-EC2-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-EC2-SAP-BYOS
wget-1.14-21.25.1
Image SLES12-SP5-EC2-SAP-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-GCE-BYOS
wget-1.14-21.25.1
Image SLES12-SP5-GCE-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-GCE-SAP-BYOS
wget-1.14-21.25.1
Image SLES12-SP5-GCE-SAP-On-Demand
wget-1.14-21.25.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
wget-1.14-21.25.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
wget-1.14-21.25.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
wget-1.14-21.25.1

Описание

Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:wget-1.14-21.25.1
Image SLES12-SP5-Azure-HPC-BYOS:wget-1.14-21.25.1
Image SLES12-SP5-Azure-HPC-On-Demand:wget-1.14-21.25.1
Image SLES12-SP5-Azure-SAP-BYOS:wget-1.14-21.25.1

Ссылки