Amazon Linux 2023 Security Advisory: ALAS-2024-657
Advisory Release Date: 2024-07-18 01:24 Pacific
Advisory Updated Date: 2024-07-22 16:00 Pacific
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent. (CVE-2024-38428)
Affected Packages:
wget
Issue Correction:
Run dnf update wget --releasever 2023.5.20240722 to update your system.
aarch64:
wget-debuginfo-1.21.3-1.amzn2023.0.4.aarch64
wget-1.21.3-1.amzn2023.0.4.aarch64
wget-debugsource-1.21.3-1.amzn2023.0.4.aarch64
src:
wget-1.21.3-1.amzn2023.0.4.src
x86_64:
wget-debuginfo-1.21.3-1.amzn2023.0.4.x86_64
wget-debugsource-1.21.3-1.amzn2023.0.4.x86_64
wget-1.21.3-1.amzn2023.0.4.x86_64