CVE-2017-6508

Name
CVE-2017-6508
Description
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch http://git.savannah.gnu.org/cgit/wget.git/commit/?id=4d729e322fae359a1aefaafec1144764a54e8ad4
Exploit http://lists.gnu.org/archive/html/bug-wget/2017-03/msg00018.html
cve@mitre.org http://www.securityfocus.com/bid/96877
cve@mitre.org https://security.gentoo.org/glsa/201706-16

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:* wget >= None <= 1.19.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wget edge-main 1.19.1-r1 None fixed
wget 3.22-main 1.19.1-r1 None fixed
wget 3.21-main 1.19.1-r1 None fixed
wget 3.20-main 1.19.1-r1 None fixed
wget 3.19-main 1.19.1-r1 None fixed
wget 3.18-main 1.19.1-r1 None fixed
wget 3.17-main 1.19.1-r1 None fixed
wget 3.12-main 1.19.1-r1 None fixed
wget 3.11-main 1.19.1-r1 None fixed
wget 3.10-main 1.19.1-r1 None fixed