Hi Tim, Fixes verified, all three look correct. Thank you for the Reported-by tags.
I will request the 4 CVE IDs and share them with you once assigned. Thanks again for the great collaboration. Best regards, Tristan Le mar. 30 juin 2026 à 09:03, Tim Rühsen <[email protected]> a écrit : > Hi Tristan > > My bad, the commits were only pushed to https://gitlab.com/gnuwget/wget. > Now pushed them to Savannah as well (both repos are / should be in sync). > > Commits are > Author: Tim Rühsen <[email protected]> > Date: Mon Jun 29 19:13:15 2026 +0200 > > * src/convert.c (html_quote_string): Fix integer+buffer overflow > > Reported-by: [email protected] > > commit 43d3ba9336bc94937e6fae2365c6ffd30c34ffcf > Author: Tim Rühsen <[email protected]> > Date: Mon Jun 29 18:57:54 2026 +0200 > > * src/http.c (parse_content_range): Fix integer overflow > > Reported-by: [email protected] > > commit 37a40fcb450153f69537c7cbc2a7a4fb0b6f7826 > Author: Tim Rühsen <[email protected]> > Date: Mon Jun 29 18:32:02 2026 +0200 > > * src/metalink.c (clean_metalink_string): Fix buffer underflow > > Reported-by: [email protected] > > > Regarding CVE assignment, would you be handling that? I collaborate with > > a CNA and could request 4 IDs if you'd prefer. > > We are not doing any CVE assignments (mostly due to lack of time). It > would be great if you could request the 4 IDs. > > > For #3, could you share the co-discoverer's name so I can include proper > > credit in the CVE record? > > Please find the details in commit c2640fe5171c59f87c58dc9fcb195b2d18b010ee > > Regards, Tim > > On 6/30/26 00:53, Tristan wrote: > > Hi Tim, > > > > Thank you for the quick fixes. Understood on #3 -- glad it's covered. > > > > I don't see the commits for #1, #2, and #4 on Savannah master yet -- > > could you let me know when they're pushed? I'd like to verify the fixes > > and would appreciate a Reported-by tag in the commit messages. > > > > Regarding CVE assignment, would you be handling that? I collaborate with > > a CNA and could request 4 IDs if you'd prefer. > > > > For #3, could you share the co-discoverer's name so I can include proper > > credit in the CVE record? > > > > Best regards, > > Tristan > > > > Le lun. 29 juin 2026 à 20:30, Tim Rühsen <[email protected] > > <mailto:[email protected]>> a écrit : > > > > Thank you very much for the report(s), Tristan! > > > > #3 has been reported privately earlier (including a patch). The patch > > has been merged today. > > > > #1, #2, #4 have been fixed in master today (please take this as > > acknowledgement for your findings). > > > > Regards, Tim > > > > > > On 6/27/26 00:06, Tristan wrote: > > > Hello, > > > > > > I am writing to report 4 memory safety vulnerabilities in GNU Wget > > > 1.25.0, all confirmed present at master HEAD on GNU Savannah > > (2026-06-20). > > > These cover the Metalink URL parser, HTTP Content-Range header > > handling, > > > iconv filename conversion, and HTML link conversion. > > > > > > Summary of findings: > > > > > > 1. Heap buffer underread in clean_metalink_string() -- crash > > (CVSS 7.5) > > > 2. Signed integer overflow in parse_content_range() -- UB/desync > > (CVSS 5.3) > > > 3. Heap buffer overflow in convert_fname() iconv E2BIG handler > > (CVSS 6.1) > > > 4. Integer overflow in html_quote_string() size counter (CVSS 5.9) > > > > > > Findings #1 and #2 are triggered by a malicious server without > user > > > interaction beyond initiating the download. Finding #3 requires > > > --remote-encoding or IRI mode. Finding #4 requires recursive > download > > > with --convert-links and a very large HTML attribute. > > > > > > All 4 have been lab-verified with AddressSanitizer and/or > > > UndefinedBehaviorSanitizer. Individual details are attached. > > > > > > I would appreciate an acknowledgment of receipt and CVE > > assignment for > > > each confirmed finding. > > > > > > Thank you and please let me know if you need anything else. > > > > > > Regards, > > > Tristan > > > >
