rpm package
almalinux/wget
pkg:rpm/almalinux/wget
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-58472 | Med | 5.9 | < 1.24.5-8.el10_2 | 1.24.5-8.el10_2 | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters | |
| CVE-2026-58471 | Med | 5.9 | < 1.24.5-8.el10_2 | 1.24.5-8.el10_2 | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When t | |
| CVE-2026-58469 | Hig | 7.5 | < 1.19.5-16.el8_10 | 1.19.5-16.el8_10 | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only U | |
| CVE-2024-38428 | Cri | 9.1 | < 1.19.5-12.el8_10 | 1.19.5-12.el8_10 | Jun 16, 2024 | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent. |
- affected < 1.24.5-8.el10_2fixed 1.24.5-8.el10_2
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters
- affected < 1.24.5-8.el10_2fixed 1.24.5-8.el10_2
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When t
- affected < 1.19.5-16.el8_10fixed 1.19.5-16.el8_10
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only U
- affected < 1.19.5-12.el8_10fixed 1.19.5-12.el8_10
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.