A utility for retrieving files using the HTTP or FTP protocols
Backport upstream fix for CVE-2026-58472 which addresses an integer and buffer overflow vulnerability in the html_quote_string() function in src/convert.c. The patch is based on upstream commits dd692d9 and f76978a, adapted to use INT_ADD_WRAPV instead of INT_ADD_OK since the gnulib version bundled with wget 1.19.5 does not provide the latter. The fix adds overflow-safe integer arithmetic to the string size calculation and aborts on overflow. Unit tests for construct_relative, match_except_index, find_fragment, and html_quote_string are included. CVE: CVE-2026-58472 Upstream patches: - |
||
|---|---|---|
| .gitignore | ||
| gating.yaml | ||
| sources | ||
| wget-1.17-path.patch | ||
| wget-1.19.5-Add-TLS-1.3-support-for-GnuTLS.patch | ||
| wget-1.19.5-ca-cert-too-verbose.patch | ||
| wget-1.19.5-covscan-important-issues.patch | ||
| wget-1.19.5-CVE-2019-5953.patch | ||
| wget-1.19.5-CVE-2024-38428.patch | ||
| wget-1.19.5-CVE-2026-58472.patch | ||
| wget-1.19.5-Don-t-limit-the-test-suite-HTTPS-server-to-TLSv1.patch | ||
| wget-1.19.5-Dont-save-userpw-with---xattr.patch | ||
| wget-1.19.5-Dont-use-extended-attributes---xattr-by-default.patch | ||
| wget-1.19.5-Enable-post-handshake-auth-under-gnutls-on-TLS1.3.patch | ||
| wget-1.19.5-no_proxy-dot-prefix.patch | ||
| wget-1.19.5-no_proxy-tests.patch | ||
| wget-1.19.5-no-log-when-quiet.patch | ||
| wget.spec | ||