GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-wget | May 29, 2018 | May 6, 2018 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-wgetamazon-linux-ami-2-upgrade-wget-debuginfo | Apr 27, 2020 | May 6, 2018 | |
| Amazon_linux | — | amazon-linux-upgrade-wget | Jun 12, 2018 | May 6, 2018 |
| Centos_linux | — | centos-upgrade-wgetcentos-upgrade-wget-debuginfo | Aug 28, 2019 | May 6, 2018 |
| Debian | debian-upgrade-wget | May 9, 2018 | May 6, 2018 | |
| Freebsd | freebsd-upgrade-package-wget | May 10, 2018 | May 8, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-wget | Jun 14, 2018 | May 6, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-wget | Sep 27, 2018 | May 6, 2018 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-wget | Sep 27, 2018 | May 6, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-entire-11-4-11-4-0-0-1-15-0 | Oct 19, 2018 | May 6, 2018 | |
| Oracle_linux | — | oracle-linux-upgrade-wget | Nov 6, 2018 | May 6, 2018 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-wgetredhat-upgrade-wget-debuginfo | Oct 31, 2018 | May 6, 2018 | |
| Suse | — | suse-upgrade-wgetsuse-upgrade-wget-openssl1 | May 20, 2018 | May 6, 2018 |
| Ubuntu | ubuntu-upgrade-wget | May 17, 2018 | May 6, 2018 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | May 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub