Logo
vulnerabilityCVE-2024-38428
Name
CVE-2024-38428
Source
NVD ( link)Debian ( link)
Description
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
wget
Patched

Vulnerability Ratings#


9.1
CVSSv31
9.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.25.0
Not Affected
buildroot
master
1.25.0
Not Affected
openwrt
master
1.25.0-r4
Not Affected
openwrt
openwrt-25.12
1.25.0-r2
Not Affected
yocto
kirkstone
1.21.4
Patched
yocto
master
1.25.0
Not Affected

Resolved with patches#


wget (yocto:kirkstone)

#
Title
Author
Resolve
1
Properly re-implement userinfo parsing (rfc2396)
=?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
CVE-2024-38428

wget (yocto:scarthgap)

#
Title
Author
Resolve
1
Properly re-implement userinfo parsing (rfc2396)
=?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de>
CVE-2024-38428