PT-2019-1762 · Gnu+5 · Wget+5
Kusano Kazuhiko
·
Published
2019-04-03
·
Updated
2024-06-15
·
CVE-2019-5953
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Wget versions 1.20.1 and earlier
Description
The issue is related to a buffer overflow in the Wget console utility, which can be exploited by a remote attacker to execute arbitrary code or cause a denial-of-service. The vulnerability is associated with the handling of specially crafted data in multibyte encoding returned by a server.
Recommendations
For GNU Wget versions 1.20.1 and earlier, update to version 1.20.3 to resolve the issue. As a temporary workaround, consider restricting the use of Wget until the update is applied.
Fix
DoS
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Wget