|
|
Log in / Subscribe / Register

Ubuntu alert USN-8543-1 (wget)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8543-1] Wget vulnerabilities
Date:  Tue, 14 Jul 2026 22:19:49 +0000
Message-ID:  <E1wjlTh-0003iI-BP@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8543-1 July 14, 2026 wget vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Wget. Software Description: - wget: retrieves files from the web Details: It was discovered that Wget mishandled semicolons in the userinfo subcomponent of a URL. A remote attacker could possibly use this issue to trick a user into connecting to a different host than intended. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428) It was discovered that Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58469) It was discovered that Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. (CVE-2026-58470) It was discovered that Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471) It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58472) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS wget 1.25.0-2ubuntu4.2 Ubuntu 24.04 LTS wget 1.21.4-1ubuntu4.3 Ubuntu 22.04 LTS wget 1.21.2-2ubuntu1.3 Ubuntu 20.04 LTS wget 1.20.3-1ubuntu2.1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS wget 1.19.4-1ubuntu2.2+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS wget 1.17.1-1ubuntu1.5+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS wget 1.15-1ubuntu1.14.04.5+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8543-1 CVE-2024-38428, CVE-2026-58469, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472 Package Information: https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.2 https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.3 https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.3


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpWtCMACgkQcpJm3tlz hgFecRAAkHYa9WPm+m+g2DAFtxIJOXdlBAYxbOYEcnqv5dIGDsSz9f+2co7ZRHD/ EORamz9xFmImCbueM3XL/XNcNHw32Q5/BE8C4dD30NOdMgshUSrRndmPOlpJooHM /Gk1U6LwMt7MPKwNoq+mW9KOvzzGx2uIgjmSXtLUiigTRWy+q6xAPz2vZD/ShbSh OVhisGr1eYdT7zd+BX7bk+NdLi6Zrnga4yJOYJKn70hKhju4lMIwjM6vpN/r5UT7 Xm+0oL0TvBBqmI7GTWk4X4x8m8GNZPt+mNMt5ZwcUDf2opQN88Z5UEi/07e5m9/k Jjkybr15dv0wzRyfLBB3Axc7Ny8xIejQaWj9XdZssoIdX34V4V1bU+kibbCEUf22 S4Q7qWVabuGWMmkRJeAddzdz/NvhFC9NcV6dzYIlx5U3gHTQ5ipPSiz/3yMMfAAs 9bT+88jRyjKkNddg7UKwdSEd/VuLdxFP09ScKesgH6HDSTah5zO5UWpPZSl37fqi FDthx+LfEv5gtkIcnTHK2oALI9ImLgIFxxzNyUWf0SVSevss7PNDJ227axJRUdqE TCpChph7MBBMU8BDm9OnSIHGBuwfxJ63v3g2tmA8VoiXKRVJSm1cQnGNx/zfNuX7 GfT8RyIu2Vv0P9/ONTRI3J8ejptUKO4D54xME1m6VsPNQ6dzl2I= =Ko4n -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds