CVE-2018-0494
published 2018-05-06CVE-2018-0494: GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
PriorityP353medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EXPLOIT
EPSS
17.04%
96.7th percentile
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wget | < wget 1.19.5-1 (bookworm) | wget 1.19.5-1 (bookworm) |
| gnu | wget | < 1.19.5 | 1.19.5 |
| gnu | wget | — | — |
| gnu | wget | >= 0 < 1.19.5-1 | 1.19.5-1 |
| gnu | wget | >= 0 < 1.19.5-1 | 1.19.5-1 |
| gnu | wget | >= 0 < 1.19.5-1 | 1.19.5-1 |
| gnu | wget | >= 0 < 1.19.5-1 | 1.19.5-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect malicious Set-Cookie headers containing embedded CRLF (\r\n) sequences followed by whitespace or tab continuation lines, which is the injection vector used to smuggle additional cookie jar entries. ↗
- →Inspect HTTP responses for Set-Cookie values that contain a quoted string with an embedded newline followed by a tab-delimited Netscape cookie jar format line (e.g., domain TRUE / FALSE <timestamp> name value), indicating an injection attempt. ↗
- →Flag wget invocations that use both --load-cookies and --save-cookies against untrusted or external URLs, as this is the precondition for the attack to succeed. ↗
- →The vulnerable code path is in the resp_new function in http.c; look for patches or binary signatures around CRLF handling in continuation lines in that function. ↗
- ·The attack only succeeds if the victim runs wget with both --load-cookies and --save-cookies pointing to the same jar file AND subsequently uses that jar against a targeted domain. Without both flags, the injected cookie cannot be leveraged. ↗
- ·Cookie replacement (overwriting an existing victim cookie) requires the attacker's server hostname to hash to a position below the targeted domain in the cookie jar hash table; otherwise the original cookie takes precedence. ↗
- ·Wget versions 1.7 through 1.19.4 are confirmed vulnerable; 1.19.5 and later contain the fix. ↗
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerability
vendor_ubuntu·2018-05-09
CVE-2018-0494 Wget vulnerability
Title: Wget vulnerability
Summary: Wget could be made to inject arbitrary cookie values.
USN-3643-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this to inject arbitrary cookie values.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Wget vulnerability
vendor_ubuntu·2018-05-09
CVE-2018-0494 Wget vulnerability
Title: Wget vulnerability
Summary: Wget could be made to inject arbitrary cookie values.
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this to inject arbitrary cookie values.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar
vendor_redhat·2018-05-06·CVSS 6.5
CVE-2018-0494 [MEDIUM] CWE-20 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar
wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
A cookie injection flaw was found in wget. An attacker can create a malicious website which, when accessed, overrides cookies belonging to arbitrary domains.
Package: wget (Red Hat Enterprise Linux 5) - Will not fix
Package: wget (Red Hat Enterprise Linux 6) - Will not fix
Package: wget (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-0494: wget - GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_...
vendor_debian·2018·CVSS 6.5
CVE-2018-0494 [MEDIUM] CVE-2018-0494: wget - GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_...
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
Scope: local
bookworm: resolved (fixed in 1.19.5-1)
bullseye: resolved (fixed in 1.19.5-1)
forky: resolved (fixed in 1.19.5-1)
sid: resolved (fixed in 1.19.5-1)
trixie: resolved (fixed in 1.19.5-1)
GHSA
GHSA-7cw3-q27m-9w5f: GNU Wget before 1
ghsa_unreviewed·2022-05-14
CVE-2018-0494 [MEDIUM] CWE-20 GHSA-7cw3-q27m-9w5f: GNU Wget before 1
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
OSV
CVE-2018-0494: GNU Wget before 1
osv·2018-05-06·CVSS 6.5
CVE-2018-0494 [MEDIUM] CVE-2018-0494: GNU Wget before 1
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
No detection rules found.
Bugzilla
CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar
bugzilla·2018-05-07·CVSS 6.5
CVE-2018-0494 [MEDIUM] CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar
CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar
It was found that GNU Wget is susceptible to a malicious web server injecting arbitrary cookies to the cookie jar file.
Normally a website should not be able to set cookies for other domains. Due to insufficient input validation GNU Wget can be tricked into storing arbitrary cookie values to the cookie jar file, bypassing this security restriction.
An external attacker is able to inject arbitrary cookie values into cookie jar file, adding new or replacing existing cookie values.
Upstream patch:
https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cd
References (PoC included):
http://openwall.com/lists/oss-security/2018/05/06/1
Discu
Bugzilla
CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar [fedora-all]
bugzilla·2018-05-07·CVSS 6.5
CVE-2018-0494 [MEDIUM] CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar [fedora-all]
CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
http://www.securityfocus.com/bid/104129http://www.securitytracker.com/id/1040838https://access.redhat.com/errata/RHSA-2018:3052https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cdhttps://lists.debian.org/debian-lts-announce/2018/05/msg00006.htmlhttps://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.htmlhttps://savannah.gnu.org/bugs/?53763https://security.gentoo.org/glsa/201806-01https://sintonen.fi/advisories/gnu-wget-cookie-injection.txthttps://usn.ubuntu.com/3643-1/https://usn.ubuntu.com/3643-2/https://www.debian.org/security/2018/dsa-4195https://www.exploit-db.com/exploits/44601/http://www.securityfocus.com/bid/104129http://www.securitytracker.com/id/1040838https://access.redhat.com/errata/RHSA-2018:3052https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cdhttps://lists.debian.org/debian-lts-announce/2018/05/msg00006.htmlhttps://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.htmlhttps://savannah.gnu.org/bugs/?53763https://security.gentoo.org/glsa/201806-01https://sintonen.fi/advisories/gnu-wget-cookie-injection.txthttps://usn.ubuntu.com/3643-1/https://usn.ubuntu.com/3643-2/https://www.debian.org/security/2018/dsa-4195https://www.exploit-db.com/exploits/44601/
2018-05-06
Published