PT-2018-3562 · Gnu+5 · Gnu Wget+5
Published
2018-12-26
·
Updated
2024-06-15
·
CVE-2018-20483
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
GNU Wget versions prior to 1.20.1
Description:
The issue is related to the
set file metadata function in xattr.c of GNU Wget, which lacks protection of metadata. This allows a local user to obtain sensitive information, such as credentials contained in a URL, by reading the user.xdg.origin.url metadata attribute of a downloaded file. Additionally, Referer information in the user.xdg.referrer.url metadata attribute is also accessible.Recommendations:
For GNU Wget versions prior to 1.20.1, update to version 1.20.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
user.xdg.origin.url and user.xdg.referrer.url metadata attributes to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Gnu Wget
Red Hat
Suse
Ubuntu