PT-2018-3562 · Gnu+5 · Gnu Wget+5

Publicado

2018-12-26

·

Atualizado

2024-06-15

·

CVE-2018-20483

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GNU Wget versions prior to 1.20.1
Description: The issue is related to the set file metadata function in xattr.c of GNU Wget, which lacks protection of metadata. This allows a local user to obtain sensitive information, such as credentials contained in a URL, by reading the user.xdg.origin.url metadata attribute of a downloaded file. Additionally, Referer information in the user.xdg.referrer.url metadata attribute is also accessible.
Recommendations: For GNU Wget versions prior to 1.20.1, update to version 1.20.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the user.xdg.origin.url and user.xdg.referrer.url metadata attributes to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2973
BDU:2020-04857
CESA-2019_3701
CVE-2018-20483
MGASA-2019-0015
OPENSUSE-SU-2019:0057-1
OPENSUSE-SU-2019_0057-1
OPENSUSE-SU-2024:11510-1
RHSA-2019:3701
RHSA-2019_3701
SUSE-SU-2019:0093-1
SUSE-SU-2019_0093-1
USN-3943-1

Produtos afetados

Alt Linux
Centos
Gnu Wget
Red Hat
Suse
Ubuntu