GNU wget CVE-2018-0494 Cookie Injection Security Bypass Vulnerability
BID:104129
CVE-2018-494 |Info
GNU wget CVE-2018-0494 Cookie Injection Security Bypass Vulnerability
| Bugtraq ID: | 104129 |
| Class: | Design Error |
| CVE: |
CVE-2018-0494 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2018 12:00AM |
| Updated: | May 06 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 GNU wget 1.19.4 GNU wget 1.19.3 GNU wget 1.19.2 GNU wget 1.19.1 GNU wget 1.11.4 GNU wget 1.11.3 GNU wget 1.11.2 GNU wget 1.11.1 GNU wget 1.10.2 GNU wget 1.10.1 GNU wget 1.10 GNU wget 1.9.1 GNU wget 1.9 GNU wget 1.8.2 GNU wget 1.8.1 GNU wget 1.8 GNU wget 1.7.1 GNU wget 1.7 GNU wget 1.19 GNU wget 1.18 GNU wget 1.17 GNU wget 1.16.3 GNU wget 1.16 GNU wget 1.15 GNU wget 1.12 GNU wget 1.11 |
| Not Vulnerable: |
GNU wget 1.19.5 |
Discussion
GNU wget CVE-2018-0494 Cookie Injection Security Bypass Vulnerability
GNU wget is prone to a remote security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
Versions prior to GNU wget 1.19.5 are vulnerable.
GNU wget is prone to a remote security-bypass vulnerability.
An attacker can leverage this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
Versions prior to GNU wget 1.19.5 are vulnerable.
Exploit / POC
GNU wget CVE-2018-0494 Cookie Injection Security Bypass Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
GNU wget CVE-2018-0494 Cookie Injection Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU wget CVE-2018-0494 Cookie Injection Security Bypass Vulnerability
References:
References:
- CVE-2018-0494 (Red Hat Bugzilla)
- GNU Wget Cookie Injection [CVE-2018-0494] (Harry Sintonen)
- Bug 1575634 - (CVE-2018-0494) CVE-2018-0494 wget: Cookie injection allows malici (Red Hat Bugzilla)
- Fix cookie injection (CVE-2018-0494) (GNU)