CVE-2018-0494 describes a cookie injection vulnerability in GNU Wget versions prior to 1.19.5, specifically within the resp_new function in http.c, exploitable via a carriage return and newline sequence in a continuation line. This vulnerability, affecting products like Canonical, Debian, GNU, and Red Hat, carries a medium CVSS score of 6.5, indicating a network-based attack with low complexity and high impact on integrity. While there is no evidence of active exploitation in the wild and it's not listed in CISA's KEV catalog, an exploit (EDB-44601) is publicly available on ExploitDB, though it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.5CPE matchmatch criteria | cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.