New Debian wget 1.21.3-1+deb12u1 fixes: This update addresses the following issue: * wget: Misinterpretation of input may lead to improper behavior (CVE-2024-38428)
--- mirror/ftp/pool/main/w/wget/wget_1.21.3-1.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/wget_1.21.3-1+deb12u1.dsc @@ -1,3 +1,9 @@ +1.21.3-1+deb12u1 [Mon, 03 Mar 2025 21:32:32 +0800] Shengqi Chen <harry@debian.org>: + + * d/control: replace obsolete B-D pkg-config with pkgconf. + * Backport patch to fix mishandling of semicolons in userinfo + (closes: CVE-2024-38428). + 1.21.3-1 [Tue, 29 Mar 2022 19:40:59 +0200] Noël Köthe <noel@debian.org>: * new upstream from 2022-02-26 <http://piuparts.knut.univention.de/5.2-1/#393240186520882050>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] e0e93e754e5 Bug #58111: wget 1.21.3-1+deb12u1 doc/errata/staging/wget.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x53>