Vulnerability Bulletins |
DSA-4195 wget - security update |
|
| Affected software | Debian |
|
Harry Sintonen discovered that wget, a network utility to retrieve filesfrom the web, does not properly handle from continuation lineswhile parsing the Set-Cookie HTTP header. A malicious web server coulduse this flaw to inject arbitrary cookies to the cookie jar file, addingnew or replacing existing cookie values. More info: https://www.debian.org/security/2018/dsa-4195 |
|






