wget CVE-2018-20483: Information leak via embedded credentials in extended file attributes

CVE-2018-20483: wget stores plaintext credentials in xattr file metadata (information-leak)

CVE-2018-20483: wget --xattr leaks URL credentials into extended attributes

CVE-2018-20483: wget --xattr leaks HTTP Basic-Auth credentials into user.xdg.origin.url

CVE-2018-20483: wget stores plaintext credentials in POSIX extended file attributes

CVE-2018-20483: wget --xattr leaks credentials via user.xdg.origin.url

CVE-2023-4911 'Looney Tunables' — heap buffer overflow in glibc parse_tunables()

criticalruntimecposted 1 day ago

glibc CVE-2023-4911 Looney Tunables Buffer Overflow

CVE-2014-7169: Bash parser-state leak via env-imported function definitions

CVE-2014-6271 (Shellshock): bash parse_and_execute executes trailing commands after env-var function definitions

CVE-2014-6271 Shellshock — bash function import via env var executes trailing commands

CVE-2014-6271 (Shellshock): Environment Variable Function Definition Injection in bash-4.3

posted 2 days ago

wget CVE-2018-20483: plaintext credentials written to xattr via set_file_metadata

CVE-2018-20483: Information Leak via Extended Attributes in wget xattr.c

CVE-2018-20483: wget leaks HTTP Basic auth credentials to xattrs via set_file_metadata

CVE-2023-43115: Ghostscript IJS device bypasses SAFER path validation

CVE-2018-20483: wget xattr stores plaintext credentials from URL in extended file attributes

Wget CVE-2018-20483 - HTTP credentials leaked via user.xdg.origin.url xattr

CVE-2023-43115 — Ghostscript IJS device bypasses SAFER for OutputFile and IjsServer

wget --xattr leaks Basic-auth credentials into POSIX xattrs (CVE-2018-20483)