Описание
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | pending | 1.25.0-2ubuntu6 |
| esm-infra-legacy/trusty | released | 1.15-1ubuntu1.14.04.5+esm2 |
| esm-infra-legacy/xenial | released | 1.17.1-1ubuntu1.5+esm3 |
| esm-infra/bionic | released | 1.19.4-1ubuntu2.2+esm3 |
| esm-infra/focal | released | 1.20.3-1ubuntu2.1+esm2 |
| jammy | released | 1.21.2-2ubuntu1.3 |
| noble | released | 1.21.4-1ubuntu4.3 |
| questing | ignored | end of life, was needs-triage |
| resolute | released | 1.25.0-2ubuntu4.2 |
| upstream | needs-triage |
Показывать по
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer ...
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
EPSS
5.3 Medium
CVSS3