USN-6852-2: Wget vulnerability
27 June 2024
Wget could be made to connect to a different host than expected.
Releases
Packages
- wget - retrieves files from the web
Details
USN-6852-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
wget
-
1.19.4-1ubuntu2.2+esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
wget
-
1.17.1-1ubuntu1.5+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.