Hi Tristan My bad, the commits were only pushed to https://gitlab.com/gnuwget/wget. Now pushed them to Savannah as well (both repos are / should be in sync).
Commits are Author: Tim Rühsen <[email protected]> Date: Mon Jun 29 19:13:15 2026 +0200 * src/convert.c (html_quote_string): Fix integer+buffer overflow Reported-by: [email protected] commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf Author: Tim Rühsen <[email protected]> Date: Mon Jun 29 18:57:54 2026 +0200 * src/http.c (parse_content_range): Fix integer overflow Reported-by: [email protected] commit 37a40fcb450153f69537c7cbc2a7a4fb0b6f7826 Author: Tim Rühsen <[email protected]> Date: Mon Jun 29 18:32:02 2026 +0200 * src/metalink.c (clean_metalink_string): Fix buffer underflow Reported-by: [email protected] > Regarding CVE assignment, would you be handling that? I collaborate with > a CNA and could request 4 IDs if you'd prefer.We are not doing any CVE assignments (mostly due to lack of time). It would be great if you could request the 4 IDs.
> For #3, could you share the co-discoverer's name so I can include proper > credit in the CVE record? Please find the details in commit c2640fe5171c59f87c58dc9fcb195b2d18b010ee Regards, Tim On 6/30/26 00:53, Tristan wrote:
Hi Tim, Thank you for the quick fixes. Understood on #3 -- glad it's covered.I don't see the commits for #1, #2, and #4 on Savannah master yet -- could you let me know when they're pushed? I'd like to verify the fixes and would appreciate a Reported-by tag in the commit messages.Regarding CVE assignment, would you be handling that? I collaborate with a CNA and could request 4 IDs if you'd prefer.For #3, could you share the co-discoverer's name so I can include proper credit in the CVE record?Best regards, TristanLe lun. 29 juin 2026 à 20:30, Tim Rühsen <[email protected] <mailto:[email protected]>> a écrit :Thank you very much for the report(s), Tristan! #3 has been reported privately earlier (including a patch). The patch has been merged today. #1, #2, #4 have been fixed in master today (please take this as acknowledgement for your findings). Regards, Tim On 6/27/26 00:06, Tristan wrote: > Hello, > > I am writing to report 4 memory safety vulnerabilities in GNU Wget > 1.25.0, all confirmed present at master HEAD on GNU Savannah (2026-06-20). > These cover the Metalink URL parser, HTTP Content-Range header handling, > iconv filename conversion, and HTML link conversion. > > Summary of findings: > > 1. Heap buffer underread in clean_metalink_string() -- crash (CVSS 7.5) > 2. Signed integer overflow in parse_content_range() -- UB/desync (CVSS 5.3) > 3. Heap buffer overflow in convert_fname() iconv E2BIG handler (CVSS 6.1) > 4. Integer overflow in html_quote_string() size counter (CVSS 5.9) > > Findings #1 and #2 are triggered by a malicious server without user > interaction beyond initiating the download. Finding #3 requires > --remote-encoding or IRI mode. Finding #4 requires recursive download > with --convert-links and a very large HTML attribute. > > All 4 have been lab-verified with AddressSanitizer and/or > UndefinedBehaviorSanitizer. Individual details are attached. > > I would appreciate an acknowledgment of receipt and CVE assignment for > each confirmed finding. > > Thank you and please let me know if you need anything else. > > Regards, > Tristan
OpenPGP_signature.asc
Description: OpenPGP digital signature
