Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 9: MGASA-2024-0378 critical: Wget remote access issue

mageia
Calendar Grey November 27, 2024
Dist Mageia Esm H88
The new notification from Mageia regarding wget highlights severe vulnerabilities impacting programs that utilize abbreviated web links.
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable

Summary

Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host. (CVE-2024-10524)

References

- https://bugs.mageia.org/show_bug.cgi?id=33780

- https://www.openwall.com/lists/oss-security/2024/11/18/6

- https://www.cve.org/CVERecord?id=CVE-2024-10524

Resolution

SRPMS

- 9/core/wget-1.21.4-1.2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0378.html
Type: security
CVE: CVE-2024-10524

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here