CVE-2024-38428

June 16, 2024, 3:15 a.m.

Product(s) Impacted

GNU Wget

  • up to 1.24.5

Description

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Weaknesses

Date

Published: June 16, 2024, 3:15 a.m.

Last Modified: June 16, 2024, 3:15 a.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

References