ALPINE-CVE-2017-6508 PUBLISHED CVSS 6.099999904632568 MEDIUM

CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.

Risk Scores

CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
Alpine:v3.15wget1.11.4-r1, 1.12-r0, 1.12-r1
Alpine:v3.17wget0, 1.11.4-r0, 1.11.4-r1
Alpine:v3.12wget1.12-r3, 0, 1.11.4-r0
Alpine:v3.10wget1.19.1-r0, 1.19-r0, 1.18-r1
Alpine:v3.21wget0, 1.11.4-r0, 1.11.4-r1
Alpine:v3.8wget1.18-r1, 1.19.1-r0, 1.19-r0
Alpine:v3.18wget1.11.4-r0, 1.14-r0, 1.19.1-r0
Alpine:v3.13wget1.11.4-r1, 1.19.1-r0, 1.19-r0
Alpine:v3.3wget1.11.4-r0, 1.17.1-r1, 1.17.1-r0
Alpine:v3.2wget1.12-r2, 0, 1.11.4-r0
Alpine:v3.4wget1.11.4-r0, 1.18-r0, 1.17.1-r1
Alpine:v3.11wget1.14-r1, 1.17-r0, 1.12-r0
Alpine:v3.22wget0, 1.19.1-r0, 1.19-r0
Alpine:v3.7wget1.14-r0, 1.11.4-r1, 1.12-r2
Alpine:v3.23wget1.12-r2, 0, 1.11.4-r0
Alpine:v3.16wget1.13.1-r1, 1.16.3-r0, 1.15-r0
Alpine:v3.20wget1.13.4-r0, 1.13.3-r0, 1.13.1-r1
Alpine:v3.9wget1.12-r2, 1.19.1-r0, 1.19-r0
Alpine:v3.14wget1.16.2-r0, 1.16.3-r0, 1.16.3-r1
Alpine:v3.6wget1.19.1-r0, 1.17.1-r0, 1.17-r0

…and 1 more

Timeline

References

Open in Interactive Console →