CVE-2024-38428
Published: 16 June 2024
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Notes
Author | Note |
---|---|
mdeslaur | using semicolons in the userinfo component isn't a common occurence, but a user could be tricked into thinking they are connecting to a different host than they are in actuality |
Priority
Status
Package | Release | Status |
---|---|---|
wget Launchpad, Ubuntu, Debian |
bionic |
Released
(1.19.4-1ubuntu2.2+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
focal |
Released
(1.20.3-1ubuntu2.1)
|
|
jammy |
Released
(1.21.2-2ubuntu1.1)
|
|
mantic |
Released
(1.21.3-1ubuntu1.1)
|
|
noble |
Released
(1.21.4-1ubuntu4.1)
|
|
trusty |
Needs triage
|
|
upstream |
Needs triage
|
|
xenial |
Released
(1.17.1-1ubuntu1.5+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
Patches: upstream: https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace |