Debian Security Advisory

DLA-1375-1 wget -- LTS security update

Date Reported:
11 May 2018
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 898076.
In Mitre's CVE dictionary: CVE-2018-0494.
More information:

Harry Sintonen have discovered a cookie injection vulnerability in wget caused by insufficient input validation, enabling an external attacker to inject arbitrary cookie values cookie jar file, adding new or replacing existing cookie values.

For Debian 7 Wheezy, these problems have been fixed in version 1.13.4-3+deb7u6.

We recommend that you upgrade your wget packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: