CVE-2024-38428

NameCVE-2024-38428
Descriptionurl.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4133-1
Debian Bugs1073523

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wget (PTS)bullseye1.21-1+deb11u1vulnerable
bullseye (security)1.21-1+deb11u2fixed
bookworm1.21.3-1+deb12u1fixed
forky, sid, trixie1.25.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wgetsourcebullseye1.21-1+deb11u2DLA-4133-1
wgetsourcebookworm1.21.3-1+deb12u1
wgetsource(unstable)1.24.5-21073523

Notes

[buster] - wget <postponed> (Minor issue, infoleak in limited conditions)
https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html
Fixed by: https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace

Search for package or bug name: Reporting problems