CVE-2017-6508
published 2017-03-07CVE-2017-6508: CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF…
PriorityP432medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
3.09%
86.2th percentile
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.19.1-2 (bookworm) | wget 1.19.1-2 (bookworm) |
| gnu | wget | <= 1.19.1 | — |
| gnu | wget | >= 0 < 1.19.1-2 | 1.19.1-2 |
| gnu | wget | >= 0 < 1.19.1-2 | 1.19.1-2 |
| gnu | wget | >= 0 < 1.19.1-2 | 1.19.1-2 |
| gnu | wget | >= 0 < 1.19.1-2 | 1.19.1-2 |
| gnu | wget | >= 0 < 1.15-1ubuntu1.14.04.3 | 1.15-1ubuntu1.14.04.3 |
| gnu | wget | >= 0 < 1.17.1-1ubuntu1.3 | 1.17.1-1ubuntu1.3 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_redhat8.0HIGH
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
puppet: Unparameterized input in multiple modules can allow a remote user to execute arbitrary code
vendor_redhat·2018-02-05·CVSS 8.0
CVE-2018-6508 [HIGH] CWE-78 puppet: Unparameterized input in multiple modules can allow a remote user to execute arbitrary code
puppet: Unparameterized input in multiple modules can allow a remote user to execute arbitrary code
Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.
Package: puppet-apache (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: puppet-mysql (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: puppet-apache (Red Hat OpenStack Platform 11 (Ocata)) - Not affected
Package: puppet-mysql (Red Hat OpenStack Platform 11 (Ocata)) - Not affected
Package: puppet-apache (Red Hat OpenStack Platform 12 (Pike)) - Not a
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2017-10-30·CVSS 8.1
CVE-2016-7098 [HIGH] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
USN-3464-1 fixed several vulnerabilities in Wget. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wget
incorrectly handled certain HTTP responses. A remote attacker could use
this issue to cause Wget to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090)
Dawid Golunski discovered that Wget incorrectly handled recursive or
mirroring mode. A remote attacker could possibly use this issue to bypass
intended access list restrictions. (CVE-2016-7098)
Orange Tsai discovered that Wget incorrectly handled CRLF sequences in
HTTP headers. A remo
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2017-10-26·CVSS 8.1
CVE-2016-7098 [HIGH] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wget
incorrectly handled certain HTTP responses. A remote attacker could use
this issue to cause Wget to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090)
Dawid Golunski discovered that Wget incorrectly handled recursive or
mirroring mode. A remote attacker could possibly use this issue to bypass
intended access list restrictions. (CVE-2016-7098)
Orange Tsai discovered that Wget incorrectly handled CRLF sequences in
HTTP headers. A remote attacker could possibly use this issue to inject
arbitrary HTTP headers. (CVE-2017-6508)
Instructions: In general, a standard system update wil
Red Hat
wget: CRLF injection in the url_parse function in url.c
vendor_redhat·2017-03-07·CVSS 6.1
CVE-2017-6508 [MEDIUM] CWE-77 wget: CRLF injection in the url_parse function in url.c
wget: CRLF injection in the url_parse function in url.c
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
A CRLF injection flaw was found in the way wget handled URLs. A remote attacker could use this flaw to inject arbitrary HTTP headers in requests, via CRLF sequences in the host sub-component of a URL, by tricking a user running wget into processing crafted URLs.
Package: wget (Red Hat Enterprise Linux 5) - Will not fix
Package: wget (Red Hat Enterprise Linux 6) - Will not fix
Package: wget (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-6508: wget - CRLF injection vulnerability in the url_parse function in url.c in Wget through ...
vendor_debian·2017·CVSS 6.1
CVE-2017-6508 [MEDIUM] CVE-2017-6508: wget - CRLF injection vulnerability in the url_parse function in url.c in Wget through ...
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
Scope: local
bookworm: resolved (fixed in 1.19.1-2)
bullseye: resolved (fixed in 1.19.1-2)
forky: resolved (fixed in 1.19.1-2)
sid: resolved (fixed in 1.19.1-2)
trixie: resolved (fixed in 1.19.1-2)
GHSA
GHSA-vmw7-mxgc-c8qm: CRLF injection vulnerability in the url_parse function in url
ghsa_unreviewed·2022-05-17
CVE-2017-6508 [MEDIUM] CWE-93 GHSA-vmw7-mxgc-c8qm: CRLF injection vulnerability in the url_parse function in url
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
OSV
wget vulnerabilities
osv·2017-10-26·CVSS 8.1
CVE-2017-13089 [HIGH] wget vulnerabilities
wget vulnerabilities
Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wget
incorrectly handled certain HTTP responses. A remote attacker could use
this issue to cause Wget to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090)
Dawid Golunski discovered that Wget incorrectly handled recursive or
mirroring mode. A remote attacker could possibly use this issue to bypass
intended access list restrictions. (CVE-2016-7098)
Orange Tsai discovered that Wget incorrectly handled CRLF sequences in
HTTP headers. A remote attacker could possibly use this issue to inject
arbitrary HTTP headers. (CVE-2017-6508)
OSV
CVE-2017-6508: CRLF injection vulnerability in the url_parse function in url
osv·2017-03-07·CVSS 6.1
CVE-2017-6508 [MEDIUM] CVE-2017-6508: CRLF injection vulnerability in the url_parse function in url
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
No detection rules found.
Bugzilla
CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c [fedora-all]
bugzilla·2017-03-07·CVSS 6.1
CVE-2017-6508 [MEDIUM] CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c [fedora-all]
CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c
bugzilla·2017-03-07·CVSS 6.1
CVE-2017-6508 [MEDIUM] CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c
CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c
CRLF injection vulnerability in the url_parse function in url.c in Wget through allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
References:
http://lists.gnu.org/archive/html/bug-wget/2017-03/msg00018.html
Upstream patch:
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=4d729e322fae359a1aefaafec1144764a54e8ad4
Discussion:
Created wget tracking bugs for this issue:
Affects: fedora-all [bug 1429986]
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=4d729e322fae359a1aefaafec1144764a54e8ad4http://lists.gnu.org/archive/html/bug-wget/2017-03/msg00018.htmlhttp://www.securityfocus.com/bid/96877https://security.gentoo.org/glsa/201706-16http://git.savannah.gnu.org/cgit/wget.git/commit/?id=4d729e322fae359a1aefaafec1144764a54e8ad4http://lists.gnu.org/archive/html/bug-wget/2017-03/msg00018.htmlhttp://www.securityfocus.com/bid/96877https://security.gentoo.org/glsa/201706-16
2017-03-07
Published