Back

CRITICAL

wget: Misinterpretation of input may lead to improper behavior

Published Jun 16, 2024

Description

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Affected products

Remediation

Red Hat statement

Only calls to Wget using semicolons in the userinfo subcomponent of a URI are vulnerable to this issue. However, this is allowed by the standard and is supported by other similar tools. To exploit this issue, an attacker must convince a local user into running Wget with a specially crafted userinfo subcomponent, limiting the exposure of this vulnerability. For these reasons, this vulnerability has been rated with a moderate severity. Additionally, this vulnerability only affects wget 1.x, wget2 is not affected.

Red Hat mitigation

Make sure to not add semicolons in the userinfo subcomponent of a URI.

Metrics

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 16, 2024
Updated Apr 21, 2025
Reserved Jun 16, 2024
CISA Vulnrichment
Updated Jul 19, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 1, 2024