HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2018-20483

CVSS 7.8v3.0pub. 2018-12-26upd. 2024-11-21

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Gnu Wget

    APP
    Gnu
    < 1.20.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-38428CRITICAL9.1PL ✓same product

GNU Wget — błędna interpretacja średnika w sekcji userinfo URI

CVE-2019-5953CRITICAL9.8PL ✓same product

Buffer overflow w GNU Wget — RCE lub DoS przez sieć

CVE-2026-58469HIGH8.7PL ✓same product

GNU Wget: heap buffer underread w przetwarzaniu URL w plikach Metalink

CVE-2017-13090HIGH8.8same product

The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked i...

CVE-2017-13089HIGH8.8same product

The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When...