6.5

CVE-2018-0494

Exploit
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Wget Version < 1.19.5
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.98% 0.968
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/104129
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1040838
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:3052
Third Party Advisory
https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cd
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2018/05/msg00006.html
Third Party Advisory
Mailing List
https://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.html
Patch
Third Party Advisory
https://savannah.gnu.org/bugs/?53763
Broken Link
https://security.gentoo.org/glsa/201806-01
Third Party Advisory
https://sintonen.fi/advisories/gnu-wget-cookie-injection.txt
Third Party Advisory
Exploit
https://usn.ubuntu.com/3643-1/
Third Party Advisory
https://usn.ubuntu.com/3643-2/
Third Party Advisory
https://www.debian.org/security/2018/dsa-4195
Third Party Advisory
https://www.exploit-db.com/exploits/44601/
Third Party Advisory
Exploit
VDB Entry