CVE-2017-6508

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-6508
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6508.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-6508
Downstream
Related
Published
2017-03-07T08:59:00.167Z
Modified
2025-11-19T17:35:27.402363Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.

References

Affected packages

Git / git.savannah.gnu.org/git/wget.git

Affected ranges

Type
GIT
Repo
http://git.savannah.gnu.org/git/wget.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected

Git / cgit.git.savannah.gnu.org/cgit/wget.git

Affected ranges

Type
GIT
Repo
https://cgit.git.savannah.gnu.org/cgit/wget.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
4d729e322fae359a1aefaafec1144764a54e8ad4