cbcvebase.
CVE-2018-0494
published 2018-05-06

CVE-2018-0494: GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EXPLOIT
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianwget< wget 1.19.5-1 (bookworm)wget 1.19.5-1 (bookworm)
gnuwget< 1.19.51.19.5
gnuwget
gnuwget>= 0 < 1.19.5-11.19.5-1
gnuwget>= 0 < 1.19.5-11.19.5-1
gnuwget>= 0 < 1.19.5-11.19.5-1
gnuwget>= 0 < 1.19.5-11.19.5-1
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM