PT-2024-4197 · Gnu+11 · Gnu Wget+11
Bachir Bendrissou
·
Published
2024-06-01
·
Updated
2026-01-20
·
CVE-2024-38428
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GNU Wget versions 1.24.5 and earlier
Description
The issue is related to the userinfo URI component manager in GNU Wget, where data intended for the userinfo subcomponent is misinterpreted as part of the host subcomponent due to insecure behavior when handling semicolons. This could allow a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations
For GNU Wget versions 1.24.5 and earlier, consider updating to a version later than 1.24.5 to resolve the issue. As a temporary workaround, avoid using semicolons in the userinfo subcomponent of a URI until a patch is available. Restrict access to sensitive information that could be impacted by this issue until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Gnu Wget
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu