CyberRota Analysis
AI-GeneratedGNU Wget versions up to 1.25.0 are susceptible to a heap buffer overflow in the convert_fname() function, which can be exploited by remote attackers through specially crafted server responses that trigger memory corruption. This vulnerability can lead to potential system compromise, making it critical for users of affected versions to prioritize patching. Organizations relying on Wget for file retrieval should assess their exposure and update to the fixed version to mitigate risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
Related CVEs
Other vulnerabilities affecting the same vendor(s)