Input validation error in wget - CVE-2024-38428
Published: June 22, 2024
wget
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Transformation Advisor
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Dell Secure Connect Gateway
IBM Cloud Pak for Business Automation
QRadar Suite
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
wget (Ubuntu package)
wget-debugsource
wget-debuginfo
wget
wget (Red Hat package)
wget-doc
wget-help
wget-lang
Business Automation Insights
IBM Cloud Pak for Watson AIOps
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
SmartFabric OS10
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
watsonx.data
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improper input validation of URL when parsing strings with semicolons within the scheme_leading_string() function in url.c. A remote attacker can pass a specially crafted URL to the application and influence its behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.