VDB

ALPINE-CVE-2018-0494

ALPINE-CVE-2018-0494 PUBLISHED CVSS 6.5 MEDIUM

GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.23wget1.18-r1, 0, 1.11.4-r0
Alpine:v3.16wget1.19.2-r1, 1.11.4-r0, 1.11.4-r1
Alpine:v3.14wget1.13.1-r0, 1.13-r0, 1.12-r4
Alpine:v3.10wget1.19.4-r2, 1.12-r4, 0
Alpine:v3.20wget1.11.4-r0, 1.11.4-r1, 1.12-r0
Alpine:v3.15wget1.12-r3, 1.19.4-r2, 1.19.4-r1
Alpine:v3.9wget1.19.4-r0, 1.11.4-r0, 1.11.4-r1
Alpine:v3.8wget1.11.4-r1, 1.12-r2, 1.12-r3
Alpine:v3.4wget1.18-r2, 1.18-r1, 1.18-r0
Alpine:v3.22wget1.14-r1, 1.14-r0, 1.13.4-r0
Alpine:v3.5wget1.14-r1, 1.16-r0, 1.16.1-r0
Alpine:v3.6wget1.14-r0, 1.15-r0, 1.16.1-r0
Alpine:v3.18wget1.13.3-r0, 1.11.4-r0, 1.11.4-r1
Alpine:v3.11wget1.11.4-r1, 1.19.2-r0, 1.19.2-r1
Alpine:v3.12wget1.11.4-r0, 1.19.4-r2, 1.19.4-r1
Alpine:v3.7wget1.19.2-r1, 0, 1.11.4-r0
Alpine:v3.21wget1.16.1-r0, 1.16.3-r1, 1.16.3-r0
Alpine:v3.19wget1.15-r0, 1.19.4-r2, 1.19.4-r1
Alpine:v3.13wget1.16.3-r0, 1.14-r1, 1.15-r0
Alpine:v3.17wget1.14-r1, 0, 1.11.4-r0

Timeline

  • May 6, 2018 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›