CVE-2024-38428

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*

History

08 Aug 2024, 15:05

Type Values Removed Values Added
References () https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace - () https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace - Mailing List, Patch
References () https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html - () https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html - Mailing List, Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Gnu wget
Gnu
CPE cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
CWE CWE-436

17 Jun 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) url.c en GNU Wget hasta 1.24.5 maneja mal los puntos y comas en el subcomponente de información de usuario de un URI y, por lo tanto, puede haber un comportamiento inseguro en el que los datos que se suponía que estaban en el subcomponente de información de usuario se malinterpretan como parte del subcomponente del host.

16 Jun 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-16 03:15

Updated : 2024-08-08 15:05


NVD link : CVE-2024-38428

Mitre link : CVE-2024-38428

CVE.ORG link : CVE-2024-38428


JSON object : View

Products Affected

gnu

  • wget
CWE
CWE-436

Interpretation Conflict