CVE-2019-5953
published 2019-05-17CVE-2019-5953: Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified…
PriorityP352critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.75%
92.2th percentile
Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.20.1-1.1 (bookworm) | wget 1.20.1-1.1 (bookworm) |
| gnu | wget | <= 1.20.1 | — |
| gnu | wget | >= 0 < 1.20.1-1.1 | 1.20.1-1.1 |
| gnu | wget | >= 0 < 1.20.1-1.1 | 1.20.1-1.1 |
| gnu | wget | >= 0 < 1.20.1-1.1 | 1.20.1-1.1 |
| gnu | wget | >= 0 < 1.20.1-1.1 | 1.20.1-1.1 |
| gnu | wget | >= 0 < 1.15-1ubuntu1.14.04.5 | 1.15-1ubuntu1.14.04.5 |
| gnu | wget | >= 0 < 1.17.1-1ubuntu1.5 | 1.17.1-1ubuntu1.5 |
| gnu | wget | >= 0 < 1.19.4-1ubuntu2.2 | 1.19.4-1ubuntu2.2 |
| the_gnu_projec | gnu_wget | — | — |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.3 | 2:7.4.1689-3ubuntu1.3 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.1 | 2:8.0.1453-1ubuntu1.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fhwx-v7qv-pjh3: Buffer overflow in GNU Wget 1
ghsa_unreviewed·2022-05-24
CVE-2019-5953 [CRITICAL] CWE-787 GHSA-fhwx-v7qv-pjh3: Buffer overflow in GNU Wget 1
Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
OSV
vim vulnerabilities
osv·2019-06-11·CVSS 9.8
CVE-2017-5953 vim vulnerabilities
vim vulnerabilities
It was discovered that Vim incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS. (CVE-2017-5953)
It was discovered that Vim incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-12735)
OSV
CVE-2019-5953: Buffer overflow in GNU Wget 1
osv·2019-05-17·CVSS 9.8
CVE-2019-5953 [CRITICAL] CVE-2019-5953: Buffer overflow in GNU Wget 1
Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
OSV
wget vulnerabilities
osv·2019-04-08·CVSS 7.8
CVE-2018-20483 [HIGH] wget vulnerabilities
wget vulnerabilities
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20483)
Kusano Kazuhiko discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-5953)
Ubuntu
Wget vulnerability
vendor_ubuntu·2019-04-09·CVSS 9.8
CVE-2019-5953 [CRITICAL] Wget vulnerability
Title: Wget vulnerability
Summary: Several security issues were fixed in Wget.
USN-3943-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Kusano Kazuhiko discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-5953)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2019-04-08·CVSS 7.8
CVE-2018-20483 [HIGH] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive
information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 18.10. (CVE-2018-20483)
Kusano Kazuhiko discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-5953)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
wget: do_conversion() heap-based buffer overflow vulnerability
vendor_redhat·2019-04-03·CVSS 9.8
CVE-2019-5953 [CRITICAL] CWE-119 wget: do_conversion() heap-based buffer overflow vulnerability
wget: do_conversion() heap-based buffer overflow vulnerability
Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
A buffer overflow flaw was found in the GNU Wget in version 1.20.1 and earlier when processing Internationalized Resource Identifiers. This flaw allows an attacker to execute arbitrary code or cause a denial of service.
Statement: This issue did not affect the versions of wget as shipped with Red Hat Enterprise Linux 5 and 6.
This issue affects the versions of wget as shipped with Red Hat Enterprise Linux 7.
Package: wget (Red Hat Enterprise Linux 5) - Not affected
Package: wget (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2019-5953: wget - Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause ...
vendor_debian·2019·CVSS 9.8
CVE-2019-5953 [CRITICAL] CVE-2019-5953: wget - Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause ...
Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.20.1-1.1)
bullseye: resolved (fixed in 1.20.1-1.1)
forky: resolved (fixed in 1.20.1-1.1)
sid: resolved (fixed in 1.20.1-1.1)
trixie: resolved (fixed in 1.20.1-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5953 wget: do_conversion() heap-based buffer overflow vulnerability [fedora-all]
bugzilla·2019-04-05·CVSS 9.8
CVE-2019-5953 [CRITICAL] CVE-2019-5953 wget: do_conversion() heap-based buffer overflow vulnerability [fedora-all]
CVE-2019-5953 wget: do_conversion() heap-based buffer overflow vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2019-5953 wget: do_conversion() heap-based buffer overflow vulnerability
bugzilla·2019-04-03·CVSS 9.8
CVE-2019-5953 [CRITICAL] CVE-2019-5953 wget: do_conversion() heap-based buffer overflow vulnerability
CVE-2019-5953 wget: do_conversion() heap-based buffer overflow vulnerability
A buffer overflow vulnerability was found in GNU Wget 1.20.1 and earlier. An attacker may be able to cause a denial-of-service (DoS) or may execute an arbitrary code.
References:
https://jvn.jp/en/jp/JVN25261088/
Discussion:
Patch:
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=692d5c5215de0db482c252492a92fc424cc6a97c
http://git.savannah.gnu.org/cgit/wget.git/commit/?id=562eacb76a2b64d5dc80a443f0f739bc9ef76c17 (cosmetic, removes debug lines)
---
Statement:
This issue did not affect the versions of wget as shipped with Red Hat Enterprise Linux 5 and 6.
This issue affects the versions of wget as shipped with Red Hat Enterprise Linux 7.
---
Created wget tracking bugs for this issue:
Affects: fedora-
http://jvn.jp/en/jp/JVN25261088/index.htmlhttps://access.redhat.com/errata/RHSA-2019:2979https://access.redhat.com/errata/RHSA-2019:3168https://security.gentoo.org/glsa/201908-19https://support.f5.com/csp/article/K14560101https://www.gnu.org/software/wget/http://jvn.jp/en/jp/JVN25261088/index.htmlhttps://access.redhat.com/errata/RHSA-2019:2979https://access.redhat.com/errata/RHSA-2019:3168https://security.gentoo.org/glsa/201908-19https://support.f5.com/csp/article/K14560101https://www.gnu.org/software/wget/
2019-05-17
Published