Cookie injection in wget - CVE-2018-0494
Published: May 8, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU12432
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0494
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files on the target system.
The weakness exists due to improper processing of Set-Cookie responses. A remote attacker can return specially crafted data and inject arbitrary cookies into the cookie jar file.
The weakness exists due to improper processing of Set-Cookie responses. A remote attacker can return specially crafted data and inject arbitrary cookies into the cookie jar file.
Affected software
wget
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Fedora
wget (Alpine package)
openSUSE Leap
wget
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Virtualization Host
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Fedora
wget (Alpine package)
openSUSE Leap
wget
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Virtualization Host
How to mitigate CVE-2018-0494
Update to version 1.19.5 or later.
wget (Alpine package) - addressed in versions 1.18-r3, 1.18-r4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
wget - addressed in versions 1.19.5-1.fc26, 1.19.5-1.fc27, 1.19.5-1.fc28
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
wget - addressed in versions 1.19.5-1.fc26, 1.19.5-1.fc27, 1.19.5-1.fc28
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Debian update for wget
- Slackware Linux update for wget
- Slackware Linux update for wget
- Slackware Linux update for wget
- OpenSUSE Linux update for wget
- Amazon Linux AMI update for wget
- Gentoo update for GNU Wget
- Red Hat update for wget
- Cookie injection in wget (Alpine package)
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for GNU Wget
- Fedora 26 update for wget
- Fedora 27 update for wget
- Fedora 28 update for wget