Bug 1226419 (CVE-2024-38428) - VUL-0: CVE-2024-38428: wget: mishandles semicolons in the userinfo subcomponent of a URI
Summary: VUL-0: CVE-2024-38428: wget: mishandles semicolons in the userinfo subcompone...
Status: IN_PROGRESS
Alias: CVE-2024-38428
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/411052/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-38428:6.2:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-17 07:41 UTC by SMASH SMASH
Modified: 2024-07-12 16:30 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-06-17 07:41:33 UTC
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-38428
https://www.cve.org/CVERecord?id=CVE-2024-38428
https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace
https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html
Comment 2 OBSbugzilla Bot 2024-06-18 15:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1226419) was mentioned in
https://build.opensuse.org/request/show/1181529 Factory / wget
Comment 7 Maintenance Automation 2024-06-21 16:30:42 UTC
SUSE-SU-2024:2154-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1226419
CVE References: CVE-2024-38428
Maintenance Incident: [SUSE:Maintenance:34428](https://smelt.suse.de/incident/34428/)
Sources used:
SUSE Linux Enterprise High Performance Computing 12 SP5 (src):
 wget-1.14-21.19.1
SUSE Linux Enterprise Server 12 SP5 (src):
 wget-1.14-21.19.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src):
 wget-1.14-21.19.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Valentin Lefebvre 2024-06-24 08:18:24 UTC
Patch backported to all affected projects. Should be good now.
Reassigned to security team. Don't hesitate to reassign to me if needed.
Comment 9 Maintenance Automation 2024-06-24 08:30:53 UTC
SUSE-SU-2024:2174-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1226419
CVE References: CVE-2024-38428
Maintenance Incident: [SUSE:Maintenance:34429](https://smelt.suse.de/incident/34429/)
Sources used:
Basesystem Module 15-SP5 (src):
 wget-1.20.3-150000.3.20.1
openSUSE Leap 15.5 (src):
 wget-1.20.3-150000.3.20.1
SUSE Linux Enterprise Micro 5.5 (src):
 wget-1.20.3-150000.3.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Maintenance Automation 2024-06-25 12:30:07 UTC
SUSE-SU-2024:2201-1: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1226419
CVE References: CVE-2024-38428
Maintenance Incident: [SUSE:Maintenance:34430](https://smelt.suse.de/incident/34430/)
Sources used:
openSUSE Leap 15.6 (src):
 wget-1.20.3-150600.19.3.1
Basesystem Module 15-SP6 (src):
 wget-1.20.3-150600.19.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Maintenance Automation 2024-07-12 16:30:35 UTC
SUSE-SU-2024:2174-2: An update that solves one vulnerability can now be installed.

Category: security (moderate)
Bug References: 1226419
CVE References: CVE-2024-38428
Maintenance Incident: [SUSE:Maintenance:34429](https://smelt.suse.de/incident/34429/)
Sources used:
SUSE Linux Enterprise Micro 5.5 (src):
 wget-1.20.3-150000.3.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.