Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-0494

Severity
6.5MEDIUM
EPSS
64.2%
top 1.56%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 6
Latest updateMay 14

Description

GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

NVDgnu/wget< 1.19.5
Debianwget< 1.19.5-1+3
CVEListV5wgetWGet

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 17.10, 18.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7cw3-q27m-9w5f: GNU Wget before 12022-05-14
CVEList
CVE-2018-0494: GNU Wget before 12018-05-06
OSV
CVE-2018-0494: GNU Wget before 12018-05-06

💥Exploits & PoCs

1
Exploit-DB
GNU wget - Cookie Injection2018-05-06

📋Vendor Advisories

4
Ubuntu
Wget vulnerability2018-05-09
Ubuntu
Wget vulnerability2018-05-09
Red Hat
wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar2018-05-06
Debian
CVE-2018-0494: wget - GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_...2018

💬Community

2
Bugzilla
CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar2018-05-07
Bugzilla
CVE-2018-0494 wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar [fedora-all]2018-05-07