CVE-2024-38428
Published: 16 June 2024
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Notes
| Author | Note |
|---|---|
| mdeslaur | using semicolons in the userinfo component isn't a common occurence, but a user could be tricked into thinking they are connecting to a different host than they are in actuality |
Priority
Status
| Package | Release | Status |
|---|---|---|
|
wget Launchpad, Ubuntu, Debian |
bionic |
Released
(1.19.4-1ubuntu2.2+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
| focal |
Released
(1.20.3-1ubuntu2.1)
|
|
| jammy |
Released
(1.21.2-2ubuntu1.1)
|
|
| mantic |
Released
(1.21.3-1ubuntu1.1)
|
|
| noble |
Released
(1.21.4-1ubuntu4.1)
|
|
| trusty |
Needs triage
|
|
| upstream |
Needs triage
|
|
| xenial |
Released
(1.17.1-1ubuntu1.5+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
|
Patches: upstream: https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace |
||