PT-2024-4197 · Gnu+11 · Gnu Wget+11

Bachir Bendrissou

·

Published

2024-06-01

·

Updated

2026-01-20

·

CVE-2024-38428

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GNU Wget versions 1.24.5 and earlier
Description The issue is related to the userinfo URI component manager in GNU Wget, where data intended for the userinfo subcomponent is misinterpreted as part of the host subcomponent due to insecure behavior when handling semicolons. This could allow a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations For GNU Wget versions 1.24.5 and earlier, consider updating to a version later than 1.24.5 to resolve the issue. As a temporary workaround, avoid using semicolons in the userinfo subcomponent of a URI until a patch is available. Restrict access to sensitive information that could be impacted by this issue until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5299
ALSA-2024:6192
ALT-PU-2024-12369
ALT-PU-2024-12470
ALT-PU-2024-12624
ALT-PU-2024-13285
AZL-42691
BDU:2024-04683
CESA-2024_5299
CVE-2024-38428
DLA-4133-1
INFSA-2024_5299
INFSA-2024_6192
MGASA-2024-0240
OESA-2024-1756
OPENSUSE-SU-2024:14056-1
OPENSUSE-SU-2024_2174-1
OPENSUSE-SU-2024_2201-1
RHSA-2024:4998
RHSA-2024:5299
RHSA-2024:6192
RHSA-2024:6208
RHSA-2024:6438
RHSA-2024_5299
RHSA-2024_6192
SUSE-SU-2024:2154-1
SUSE-SU-2024:2174-1
SUSE-SU-2024:2174-2
SUSE-SU-2024:2201-1
SUSE-SU-2024_2154-1
SUSE-SU-2024_2174-1
SUSE-SU-2024_2201-1
SUSE-SU-2025:20010-1
USN-6852-1
USN-6852-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Gnu Wget
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu