Bug#917375: wget: CVE-2018-20483

2018-12-27 Thread Salvatore Bonaccorso
Source: wget Source-Version: 1.20.1-1 On Wed, Dec 26, 2018 at 09:24:23PM +0100, Salvatore Bonaccorso wrote: > Source: wget > Version: 1.20-1 > Severity: important > Tags: security upstream > > Hi, > > The following vulnerability was published for wget. > > CVE-2018-20483[0]: > |

Bug#917375: wget: CVE-2018-20483

2018-12-26 Thread Salvatore Bonaccorso
Control: severity -1 serious Hi I would agree RC severity is not strongly warranted, but raising the issue as the change is overviewable, and upstream released a fix, and RC severity set to quarantee buster will have the fix. If you though disagree, feel free to downgrade again. Upstream fixed

Bug#917375: wget: CVE-2018-20483

2018-12-26 Thread Salvatore Bonaccorso
Source: wget Version: 1.20-1 Severity: important Tags: security upstream Hi, The following vulnerability was published for wget. CVE-2018-20483[0]: | set_file_metadata in xattr.c in GNU Wget through 1.20 stores a file's | origin URL in the user.xdg.origin.url metadata attribute of the |