Hi Tristan

My bad, the commits were only pushed to https://gitlab.com/gnuwget/wget.
Now pushed them to Savannah as well (both repos are / should be in sync).

Commits are
Author: Tim Rühsen <[email protected]>
Date:   Mon Jun 29 19:13:15 2026 +0200

    * src/convert.c (html_quote_string): Fix integer+buffer overflow

    Reported-by: [email protected]

commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
Author: Tim Rühsen <[email protected]>
Date:   Mon Jun 29 18:57:54 2026 +0200

    * src/http.c (parse_content_range): Fix integer overflow

    Reported-by: [email protected]

commit 37a40fcb450153f69537c7cbc2a7a4fb0b6f7826
Author: Tim Rühsen <[email protected]>
Date:   Mon Jun 29 18:32:02 2026 +0200

    * src/metalink.c (clean_metalink_string): Fix buffer underflow

    Reported-by: [email protected]

> Regarding CVE assignment, would you be handling that? I collaborate with
> a CNA and could request 4 IDs if you'd prefer.

We are not doing any CVE assignments (mostly due to lack of time). It would be great if you could request the 4 IDs.

> For #3, could you share the co-discoverer's name so I can include proper
> credit in the CVE record?

Please find the details in commit c2640fe5171c59f87c58dc9fcb195b2d18b010ee

Regards, Tim

On 6/30/26 00:53, Tristan wrote:
Hi Tim,

Thank you for the quick fixes. Understood on #3 -- glad it's covered.

I don't see the commits for #1, #2, and #4 on Savannah master yet -- could you let me know when they're pushed? I'd like to verify the fixes and would appreciate a Reported-by tag in the commit messages.

Regarding CVE assignment, would you be handling that? I collaborate with a CNA and could request 4 IDs if you'd prefer.

For #3, could you share the co-discoverer's name so I can include proper credit in the CVE record?

Best regards,
Tristan

Le lun. 29 juin 2026 à 20:30, Tim Rühsen <[email protected] <mailto:[email protected]>> a écrit :

    Thank you very much for the report(s), Tristan!

    #3 has been reported privately earlier (including a patch). The patch
    has been merged today.

    #1, #2, #4 have been fixed in master today (please take this as
    acknowledgement for your findings).

    Regards, Tim


    On 6/27/26 00:06, Tristan wrote:
     > Hello,
     >
     > I am writing to report 4 memory safety vulnerabilities in GNU Wget
     > 1.25.0, all confirmed present at master HEAD on GNU Savannah
    (2026-06-20).
     > These cover the Metalink URL parser, HTTP Content-Range header
    handling,
     > iconv filename conversion, and HTML link conversion.
     >
     > Summary of findings:
     >
     > 1. Heap buffer underread in clean_metalink_string() -- crash
    (CVSS 7.5)
     > 2. Signed integer overflow in parse_content_range() -- UB/desync
    (CVSS 5.3)
     > 3. Heap buffer overflow in convert_fname() iconv E2BIG handler
    (CVSS 6.1)
     > 4. Integer overflow in html_quote_string() size counter (CVSS 5.9)
     >
     > Findings #1 and #2 are triggered by a malicious server without user
     > interaction beyond initiating the download. Finding #3 requires
     > --remote-encoding or IRI mode. Finding #4 requires recursive download
     > with --convert-links and a very large HTML attribute.
     >
     > All 4 have been lab-verified with AddressSanitizer and/or
     > UndefinedBehaviorSanitizer. Individual details are attached.
     >
     > I would appreciate an acknowledgment of receipt and CVE
    assignment for
     > each confirmed finding.
     >
     > Thank you and please let me know if you need anything else.
     >
     > Regards,
     > Tristan


Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to