Information disclosure in wget - CVE-2018-20483
Published: January 2, 2019
Vulnerability details
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to set_file_metadata in xattr.c stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file. A local attacker can read this attribute, as demonstrated by getfattr and obtain credentials contained in the URL.
Affected software
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
wget (Alpine package)
wget (Ubuntu package)
wget
curl
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2018-20483
wget (Alpine package) - update to 1.20.1-r0
wget (Ubuntu package) - addressed in versions 1.15-1ubuntu1.14.04.5, 1.17.1-1ubuntu1.5, 1.19.4-1ubuntu2.2, 1.19.5-1ubuntu1.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
wget - addressed in versions 1.20.1-1.fc28, 1.20.1-1.fc29
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
curl - update to 7.61.1-7.fc29
External References
Related Security Bulletins
- Information disclosure in GNU wget
- OpenSUSE Linux update for wget
- Amazon Linux AMI update for curl
- Ubuntu update for Wget
- Gentoo update for GNU Wget
- Red Hat update for curl
- Information disclosure in wget (Alpine package)
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for GNU wget
- Information disclosure in IBM Watson Discovery
- Fedora 28 update for wget
- Fedora 29 update for wget
- Fedora 29 update for curl