diff --git a/patchinfo.20240709130932955043.255638743075857/_patchinfo b/patchinfo.20240709130932955043.255638743075857/_patchinfo new file mode 100644 index 0000000..66e9e71 --- /dev/null +++ b/patchinfo.20240709130932955043.255638743075857/_patchinfo @@ -0,0 +1,24 @@ + + + VUL-0: CVE-2024-38428: wget: mishandles semicolons in the userinfo subcomponent of a URI + + vlefebvre + moderate + security + Security update for wget + This update for wget fixes the following issues: + +- CVE-2024-38428: Fix mishandled semicolons in the userinfo subcomponent of a URI. (bsc#1226419) + +- Update to GNU wget 1.24.5: + * Fix how subdomain matches are checked for HSTS. + * Wget will now also parse the srcset attribute in <source> HTML tags + * Support reading fetchmail style "user" and "passwd" fields from netrc + * In some cases, prevent the confusing "Cannot write to... (success)" error messages + * Support extremely fast download speeds (TB/s) + * Ensure that CSS URLs are corectly quoted + * libproxy support is now upstream- drop wget-libproxy.patch + + wget + +