Vulnerability Bulletins

DSA-4195 wget - security update

   
Affected software Debian
 
Harry Sintonen discovered that wget, a network utility to retrieve filesfrom the web, does not properly handle
from continuation lineswhile parsing the Set-Cookie HTTP header. A malicious web server coulduse this flaw to inject arbitrary cookies to the cookie jar file, addingnew or replacing existing cookie values.

More info:

https://www.debian.org/security/2018/dsa-4195