ALAS-2024-657


Amazon Linux 2023 Security Advisory: ALAS-2024-657
Advisory Release Date: 2024-07-18 01:24 Pacific
Advisory Updated Date: 2024-07-22 16:00 Pacific
Severity: Medium

Issue Overview:

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent. (CVE-2024-38428)


Affected Packages:

wget


Issue Correction:
Run dnf update wget --releasever 2023.5.20240722 to update your system.

New Packages:
aarch64:
    wget-debuginfo-1.21.3-1.amzn2023.0.4.aarch64
    wget-1.21.3-1.amzn2023.0.4.aarch64
    wget-debugsource-1.21.3-1.amzn2023.0.4.aarch64

src:
    wget-1.21.3-1.amzn2023.0.4.src

x86_64:
    wget-debuginfo-1.21.3-1.amzn2023.0.4.x86_64
    wget-debugsource-1.21.3-1.amzn2023.0.4.x86_64
    wget-1.21.3-1.amzn2023.0.4.x86_64