Cookie injection in wget - CVE-2018-0494

 

Cookie injection in wget - CVE-2018-0494

Published: May 8, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU12432
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0494
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary files on the target system.

The weakness exists due to improper processing of Set-Cookie responses. A remote attacker can return specially crafted data and inject arbitrary cookies into the cookie jar file.

Affected software

wget
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Slackware Linux
Fedora
wget (Alpine package)
openSUSE Leap
wget
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Virtualization Host

How to mitigate CVE-2018-0494

Update to version 1.19.5 or later.

wget (Alpine package) - addressed in versions 1.18-r3, 1.18-r4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
wget - addressed in versions 1.19.5-1.fc26, 1.19.5-1.fc27, 1.19.5-1.fc28

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins