CyberRota Analysis
AI-GeneratedGNU Wget versions up to 1.25.0 are vulnerable due to an integer overflow in the parse_content_range() function, which can be exploited by attackers through crafted Content-Range header values. This vulnerability may lead to undefined behavior and potential desynchronization during downloads, posing a risk to the integrity of data retrieval processes. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
Related CVEs
Other vulnerabilities affecting the same vendor(s)