CVE-2018-20483
published 2018-12-26CVE-2018-20483: set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of…
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.66%
47.4th percentile
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.20.1-1 (bookworm) | wget 1.20.1-1 (bookworm) |
| gnu | wget | < 1.20.1 | 1.20.1 |
| gnu | wget | >= 0 < 1.20.1-1 | 1.20.1-1 |
| gnu | wget | >= 0 < 1.20.1-1 | 1.20.1-1 |
| gnu | wget | >= 0 < 1.20.1-1 | 1.20.1-1 |
| gnu | wget | >= 0 < 1.20.1-1 | 1.20.1-1 |
| gnu | wget | >= 0 < 1.15-1ubuntu1.14.04.5 | 1.15-1ubuntu1.14.04.5 |
| gnu | wget | >= 0 < 1.17.1-1ubuntu1.5 | 1.17.1-1ubuntu1.5 |
| gnu | wget | >= 0 < 1.19.4-1ubuntu2.2 | 1.19.4-1ubuntu2.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2019-04-08·CVSS 7.8
CVE-2018-20483 [HIGH] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20483)
Kusano Kazuhiko discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-5953)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
wget: Information exposure in set_file_metadata function in xattr.c
vendor_redhat·2018-12-26·CVSS 7.8
CVE-2018-20483 [HIGH] CWE-200 wget: Information exposure in set_file_metadata function in xattr.c
wget: Information exposure in set_file_metadata function in xattr.c
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
Mitigation: wget users should pass credentials using the "--user/password" or the "--user/--ask-password" command line argument to wget or use --no-xattr to turn o
Debian
CVE-2018-20483: wget - set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin UR...
vendor_debian·2018·CVSS 7.8
CVE-2018-20483 [HIGH] CVE-2018-20483: wget - set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin UR...
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
Scope: local
bookworm: resolved (fixed in 1.20.1-1)
bullseye: resolved (fixed in 1.20.1-1)
forky: resolved (fixed in 1.20.1-1)
sid: resolved (fixed in 1.20.1-1)
trixie: resolved (fixed in 1.20.1-1)
GHSA
GHSA-mxm6-6r3r-6wj4: set_file_metadata in xattr
ghsa_unreviewed·2022-05-13
CVE-2018-20483 [HIGH] CWE-200 GHSA-mxm6-6r3r-6wj4: set_file_metadata in xattr
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
OSV
wget vulnerabilities
osv·2019-04-08·CVSS 7.8
CVE-2018-20483 [HIGH] wget vulnerabilities
wget vulnerabilities
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20483)
Kusano Kazuhiko discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-5953)
OSV
CVE-2018-20483: set_file_metadata in xattr
osv·2018-12-26·CVSS 7.8
CVE-2018-20483 [HIGH] CVE-2018-20483: set_file_metadata in xattr
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20483 wget: Information exposure in set_file_metadata function in xattr.c [fedora-all]
bugzilla·2019-01-02·CVSS 7.8
CVE-2018-20483 [HIGH] CVE-2018-20483 wget: Information exposure in set_file_metadata function in xattr.c [fedora-all]
CVE-2018-20483 wget: Information exposure in set_file_metadata function in xattr.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2018-20483 curl: wget: Information exposure in set_file_metadata function in xattr.c [fedora-all]
bugzilla·2019-01-02·CVSS 7.8
CVE-2018-20483 [HIGH] CVE-2018-20483 curl: wget: Information exposure in set_file_metadata function in xattr.c [fedora-all]
CVE-2018-20483 curl: wget: Information exposure in set_file_metadata function in xattr.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2018-20483 wget: Information exposure in set_file_metadata function in xattr.c
bugzilla·2018-12-31·CVSS 7.8
CVE-2018-20483 [HIGH] CVE-2018-20483 wget: Information exposure in set_file_metadata function in xattr.c
CVE-2018-20483 wget: Information exposure in set_file_metadata function in xattr.c
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
References:
http://git.savannah.gnu.org/cgit/wget.git/tree/NEWS
Upstream patches:
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=c125d24762
http://git.savannah.gnu.org/cgit/wget.git/tree/NEWShttp://www.securityfocus.com/bid/106358https://access.redhat.com/errata/RHSA-2019:3701https://security.gentoo.org/glsa/201903-08https://security.netapp.com/advisory/ntap-20190321-0002/https://twitter.com/marcan42/status/1077676739877232640https://usn.ubuntu.com/3943-1/http://git.savannah.gnu.org/cgit/wget.git/tree/NEWShttp://www.securityfocus.com/bid/106358https://access.redhat.com/errata/RHSA-2019:3701https://security.gentoo.org/glsa/201903-08https://security.netapp.com/advisory/ntap-20190321-0002/https://twitter.com/marcan42/status/1077676739877232640https://usn.ubuntu.com/3943-1/
2018-12-26
Published