Mageia alert MGASA-2024-0378 (wget)
| From: | Mageia Updates <updates-announce@ml.mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2024-0378: Updated wget packages fix security vulnerability | |
| Date: | Wed, 27 Nov 2024 20:59:52 +0100 | |
| Message-ID: | <20241127195952.D02139FE2E@duvel.mageia.org> | |
| Archive-link: | Article |
MGASA-2024-0378 - Updated wget packages fix security vulnerability Publication date: 27 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0378.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-10524 Description: Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host. (CVE-2024-10524) References: - https://bugs.mageia.org/show_bug.cgi?id=33780 - https://www.openwall.com/lists/oss-security/2024/11/18/6 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1... SRPMS: - 9/core/wget-1.21.4-1.2.mga9
