Input validation error in wget - CVE-2024-38428

 

Input validation error in wget - CVE-2024-38428

Published: June 22, 2024


Vulnerability identifier: #VU93077
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38428
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper input validation of URL when parsing strings with semicolons within the scheme_leading_string() function in url.c. A remote attacker can pass a specially crafted URL to the application and influence its behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.


Affected software

wget
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Transformation Advisor
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Dell Secure Connect Gateway
IBM Cloud Pak for Business Automation
QRadar Suite
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
wget (Ubuntu package)
wget-debugsource
wget-debuginfo
wget
wget (Red Hat package)
wget-doc
wget-help
wget-lang
Business Automation Insights
IBM Cloud Pak for Watson AIOps
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
SmartFabric OS10
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
watsonx.data
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2024-38428

Install updates from vendor's website.

QRadar Suite - addressed in versions 1.10.26.0, 1.10.27.0
IBM Process Mining - update to 2.0
IBM Cloud Transformation Advisor - update to 3.10.2
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Business Automation Insights - update to 24.0.0.0.2
wget (Ubuntu package) - update to Ubuntu Pro
Migration Toolkit for Containers - update to 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.12.6, 1.13.2
wget-debugsource - addressed in versions 1.14-21.19.1, 1.20.3-150000.3.20.1, 1.20.3-150600.19.3.1
wget-debuginfo - addressed in versions 1.14-21.19.1, 1.20.3-150000.3.20.1, 1.20.3-150600.19.3.1
wget - addressed in versions 1.14-21.19.1, 1.20.3-150000.3.20.1, 1.20.3-150600.19.3.1
wget (Red Hat package) - addressed in versions 1.19.5-10.el8_6.2, 1.21.1-7.el9_2.1
wget - update to 1.19.5-12.0.1
wget-doc - update to 1.19.5-12.0.1
wget - update to 1.20.3-5
wget-help - update to 1.20.3-5
wget-debugsource - update to 1.20.3-5
wget-debuginfo - update to 1.20.3-5
wget-lang - addressed in versions 1.20.3-150000.3.20.1, 1.20.3-150600.19.3.1
watsonx.data - update to 2.0.3
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.01.00
Red Hat OpenShift Dev Spaces - update to 3.16.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.63, 4.13.48, 4.13.51, 4.14.36, 4.14.38, 4.15.32, 4.15.33, 4.16.12, 4.16.13, 4.16.15, 4.16.44, 4.17.0
OpenShift Virtualization - addressed in versions 4.13.11, 4.15.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.12, 4.14.11, 4.16.2
App Connect Enterprise Certified Container - addressed in versions 5.0.21, 12.0.4, 12.4.0
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF03
SmartFabric OS10 - update to 10.6.0.3
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins