This bug was fixed in the package wget - 1.25.0-3ubuntu1
---------------
wget (1.25.0-3ubuntu1) stonking; urgency=medium
* Merge with Debian unstable (LP: #2163536). Remaining changes:
- d/rules: pass --with-ssl=openssl
- d/p/wget-maybe-prepend-scheme-only-in-verbose-mode: Print message only in
verbose mode (LP #2122484).
- SECURITY UPDATE: Buffer overflow in metalink.
+ debian/patches/CVE-2026-58469.patch: Fix buffer overflow in
src/metalink.c
+ CVE-2026-58469
- SECURITY UPDATE: Integer overflow in http
+ debian/patches/CVE-2026-58470.patch: Fix integer overflow in src/http.c
+ CVE-2026-58470
- SECURITY UPDATE: Buffer overflow in convert_fname.
+ debian/patches/CVE-2026-58471.patch: Fix buffer overflow in src/url.c
+ CVE-2026-58471
- SECURITY UPDATE: Integer and buffer overflow in html_quote_string.
+ debian/patches/CVE-2026-58472.patch: Fix integer+buffer overflow in
src/convert.c
+ CVE-2026-58472
- SECURITY REGRESSION: Incomplete fix for CVE-2026-58472 (LP #2163754)
+ debian/patches/CVE-2026-58472-post1.patch: Fix buffer overflow in
src/convert.c
wget (1.25.0-3) unstable; urgency=medium
* patch from upstream git to fix CVE-2026-15146 a problem with IP
validation in FTP PASV. closes: Bug#1142284
-- Ural Tunaboyu <[email protected]> Tue, 25 Aug 2026 17:45:24 -0700
** Changed in: wget (Ubuntu)
Status: New => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-15146
** CVE added: https://cve.org/CVERecord?id=CVE-2026-58469
** CVE added: https://cve.org/CVERecord?id=CVE-2026-58470
** CVE added: https://cve.org/CVERecord?id=CVE-2026-58471
** CVE added: https://cve.org/CVERecord?id=CVE-2026-58472
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163536
Title:
Merge wget 1.25.0-3 from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/wget/+bug/2163536/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs