Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 655216 (CVE-2018-0494) - <net-misc/wget-1.19.5: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar (CVE-2018-0494)
Summary: <net-misc/wget-1.19.5: Cookie injection allows malicious website to write arb...
Status: RESOLVED FIXED
Alias: CVE-2018-0494
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://lists.gnu.org/archive/html/bug...
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2018-05-07 20:10 UTC by Lars Wendler (Polynomial-C) (RETIRED)
Modified: 2018-06-13 20:54 UTC (History)
2 users (show)

See Also:
Package list:
=net-misc/wget-1.19.5
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2018-05-07 20:10:55 UTC
From the announcement mail:

This version fixes CVE-2018-0494 (Cookie injection vulnerability) found
by Harry Sintonen.
Comment 1 Mart Raudsepp gentoo-dev 2018-05-07 21:26:21 UTC
arm64 stable
Comment 2 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2018-05-07 21:40:04 UTC
amd64 stable
Comment 3 matoro archtester 2018-05-07 22:10:27 UTC
commit a9c5234 builds amd64 but dies on armv7 with:

sed -i -e "s:/usr/local/etc:${EPREFIX}/etc:g" "${ED%/}"/etc/wgetrc "${ED%/}"/usr/share/man/man1/wget.1 "${ED%/}"/usr/share/info/wget.info || die
sed: can't read /var/tmp/portage/net-misc/wget-1.19.5/image/usr/share/man/man1/wget.1: No such file or directory
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2018-05-07 23:55:54 UTC
x86 stable
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2018-05-08 19:09:20 UTC
commit 282e621f25cad8aa8f0b9f0ba8244e495de522e0
Author: Jeroen Roovers <jer@gentoo.org>
Date:   Tue May 8 14:43:49 2018 +0200

    net-misc/wget: Stable for HPPA too.
Comment 6 Larry the Git Cow gentoo-dev 2018-05-08 21:16:54 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5927c6b572288cc5be84b20082fa70658e9884cc

commit 5927c6b572288cc5be84b20082fa70658e9884cc
Author:     Rolf Eike Beer <eike@sf-mail.de>
AuthorDate: 2018-05-08 19:38:50 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-05-08 21:16:33 +0000

    net-misc/wget: stable 1.19.5 for sparc
    
    Bug: https://bugs.gentoo.org/655216
    Package-Manager: Portage-2.3.24, Repoman-2.3.6
    RepoMan-Options: --include-arches="sparc"

 net-misc/wget/wget-1.19.5.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 7 Larry the Git Cow gentoo-dev 2018-05-11 21:59:16 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=89a911feff2f70be994d6b3b043dd25d37f85ae7

commit 89a911feff2f70be994d6b3b043dd25d37f85ae7
Author:     Sergei Trofimovich <slyfox@gentoo.org>
AuthorDate: 2018-05-11 21:59:06 +0000
Commit:     Sergei Trofimovich <slyfox@gentoo.org>
CommitDate: 2018-05-11 21:59:10 +0000

    net-misc/wget: stable 1.19.5 for ia64, bug #655216
    
    Bug: https://bugs.gentoo.org/655216
    Package-Manager: Portage-2.3.36, Repoman-2.3.9
    RepoMan-Options: --include-arches="ia64"

 net-misc/wget/wget-1.19.5.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 8 Tobias Klausmann (RETIRED) gentoo-dev 2018-05-14 19:21:38 UTC
Stable on alpha.
Comment 9 Michael Boyle 2018-06-12 02:44:14 UTC
GLSA request filed
Comment 10 GLSAMaker/CVETool Bot gentoo-dev 2018-06-13 20:54:09 UTC
This issue was resolved and addressed in
 GLSA 201806-01 at https://security.gentoo.org/glsa/201806-01
by GLSA coordinator Aaron Bauman (b-man).