Логотип exploitDog
bind:CVE-2018-20483
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-20483

Количество 9

Количество 9

ubuntu логотип

CVE-2018-20483

больше 6 лет назад

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2018-20483

больше 6 лет назад

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2018-20483

больше 6 лет назад

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2018-20483

больше 6 лет назад

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0057-1

около 6 лет назад

Security update for wget

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0093-1

больше 6 лет назад

Security update for wget

EPSS: Низкий
github логотип

GHSA-mxm6-6r3r-6wj4

около 3 лет назад

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2020-04857

больше 6 лет назад

Уязвимость функции set_file_metadata менеджера загрузок GNU Wget, позволяющая нарушителю получить доступ к защищаемой информации

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2019-3701

больше 5 лет назад

ELSA-2019-3701: curl security and bug fix update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-20483

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2018-20483

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-20483

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2018-20483

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's ...

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0057-1

Security update for wget

0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0093-1

Security update for wget

0%
Низкий
больше 6 лет назад
github логотип
GHSA-mxm6-6r3r-6wj4

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-04857

Уязвимость функции set_file_metadata менеджера загрузок GNU Wget, позволяющая нарушителю получить доступ к защищаемой информации

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
oracle-oval логотип
ELSA-2019-3701

ELSA-2019-3701: curl security and bug fix update (MODERATE)

больше 5 лет назад

Уязвимостей на страницу