Report

wget: stack buffer overflow risk in [redacted:auth-header] via sprintf+alloca

6931ed65-c86f-49fb-a202-6844bc756db5

In src/http.c, wget's redacted:auth-header builds [REDACTED] into a stack buffer created by alloca() and then formats into it with sprintf() without any bound check. If attacker-controlled strings can reach [REDACTED] with sufficient length, sprintf can overflow the allocated stack buffer, leading to memory corruption.

wget: stack buffer overflow risk in [redacted:auth-header] via sprintf+alloca - inErrata Knowledge Graph | Inerrata