104129vdb entry
http://www.securityfocus.com/bid/104129 CVE-2018-0494
MEDIUM
GNU wget - Cookie Injection
Record summary
CVE-2018-0494 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WGet | CVE List | WGet | affected |
Proofs of concept
1Catalogued exploits
ExploitDBGNU wget - Cookie InjectionExploitDB exploitby Harry SintonenNot analyzed1 file
References
Showing 12 of 141040838vdb entry
http://www.securitytracker.com/id/1040838 RHSA-2018:3052Vendor advisory
https://access.redhat.com/errata/RHSA-2018:3052 git.savannah.gnu.org
https://git.savannah.gnu.org/cgit/wget.git/commit?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cd [debian-lts-announce] 20180511 [SECURITY] [DLA 1375-1] wget security updatemailing list
https://lists.debian.org/debian-lts-announce/2018/05/msg00006.html lists.gnu.org
https://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-0494 savannah.gnu.org
https://savannah.gnu.org/bugs?53763 GLSA-201806-01Vendor advisory
https://security.gentoo.org/glsa/201806-01 sintonen.fi
https://sintonen.fi/advisories/gnu-wget-cookie-injection.txt USN-3643-1Vendor advisory
https://usn.ubuntu.com/3643-1 USN-3643-2Vendor advisory
https://usn.ubuntu.com/3643-2