DescriptionBuffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
NVD severityhigh (attack range: remote)
Debian Bugs926389

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wget (PTS)jessie1.16-1+deb8u5vulnerable
jessie (security)1.16-1+deb8u6fixed
stretch (security), stretch1.18-5+deb9u3fixed
buster, sid1.20.1-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs

Notes (removed unneeded debug lines in fixing commit)
Fixed in 1.20.3

