PT-2026-56241 · Gnu+3 · Wget+3
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Wget versions prior to 1.25.0 commit dd692d9
Description
A heap buffer overflow occurs in the
html quote string() function within src/convert.c. A remote attacker can trigger memory corruption by providing a crafted HTML attribute containing a large number of characters that require entity encoding. This causes a signed integer counter to overflow during the accumulation of the output size, leading to an undersized heap allocation and a subsequent buffer overflow during the copy phase.Recommendations
Update GNU Wget to the version containing commit dd692d9.
Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Rocky Linux
Ubuntu
Wget