This series backports five security fixes for wget 1.25.0:
- CVE-2026-58469: buffer underflow in metalink string trimming
(clean_metalink_string)
- CVE-2026-58470: integer overflow in HTTP Content-Range header parsing
(parse_content_range)
- CVE-2026-58471: buffer overflow in filename encoding conversion
(convert_fname)
- CVE-2026-58472: integer and buffer overflow in HTML entity quoting
(html_quote_string)
- CVE-2026-15146: SSRF via FTP PASV/LPSV response address spoofing
(ftp_pasv, ftp_lpsv)
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241608):
https://lists.openembedded.org/g/openembedded-core/message/241608
Mute This Topic: https://lists.openembedded.org/mt/120390803/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-