Hide Forgot
A buffer overflow vulnerability was found in GNU Wget 1.20.1 and earlier. An attacker may be able to cause a denial-of-service (DoS) or may execute an arbitrary code. References: https://jvn.jp/en/jp/JVN25261088/
Patch: http://git.savannah.gnu.org/cgit/wget.git/commit/?id=692d5c5215de0db482c252492a92fc424cc6a97c http://git.savannah.gnu.org/cgit/wget.git/commit/?id=562eacb76a2b64d5dc80a443f0f739bc9ef76c17 (cosmetic, removes debug lines)
Statement: This issue did not affect the versions of wget as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the versions of wget as shipped with Red Hat Enterprise Linux 7.
Created wget tracking bugs for this issue: Affects: fedora-all [bug 1696738]
The new buffer overflow bug fixed upstream in versions 1.20.2 and 1.20.3 http://lists.gnu.org/archive/html/bug-wget/2019-04/msg00001.html http://lists.gnu.org/archive/html/bug-wget/2019-04/msg00015.html
The vulnerability is a heap-based buffer overflow within the "do_conversion()" function in src/iri.c when processing Internationalized Resource Identifiers. An attacker can exploit this vulnerability to cause a crash and, potentially, execute arbitrary code by, for example, tricking a user into recursively downloading a specially crafted website. Upstream announced a fix for this issue as part of version 1.20.2. However, this version did not actually contain the necessary code changes, thus leaving version 1.20.2 vulnerable. Version 1.20.3 fixed this.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:0983 https://access.redhat.com/errata/RHSA-2019:0983
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1228 https://access.redhat.com/errata/RHSA-2019:1228
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.5 Extended Update Support Via RHSA-2019:2979 https://access.redhat.com/errata/RHSA-2019:2979
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.4 Advanced Update Support Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions Red Hat Enterprise Linux 7.4 Telco Extended Update Support Via RHSA-2019:3168 https://access.redhat.com/errata/RHSA-2019:3168