{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/alpinelinux3.18els/vex/2018/cve-2018-0494-els_os-alpinelinux3_18els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-03T19:29:00Z",
      "generator": {
        "date": "2026-07-03T19:29:00Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2018-0494-ELS_OS-ALPINELINUX3.18ELS",
      "initial_release_date": "2018-05-06T22:29:00Z",
      "revision_history": [
        {
          "date": "2018-05-06T22:29:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-05-27T14:29:57Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-03T19:29:00Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2018-0494"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-doc-1.21.4-r0.x86_64",
                "product": {
                  "name": "wget-doc-1.21.4-r0.x86_64",
                  "product_id": "wget-doc-1.21.4-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/wget-doc@1.21.4-r0?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-1.21.4-r0.x86_64",
                "product": {
                  "name": "wget-1.21.4-r0.x86_64",
                  "product_id": "wget-1.21.4-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/wget@1.21.4-r0?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.18",
                "product": {
                  "name": "Alpine Linux 3.18",
                  "product_id": "Alpine-Linux-3.18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.18:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-doc-1.21.4.tuxcare.els1-r0.x86_64",
                "product": {
                  "name": "wget-doc-1.21.4.tuxcare.els1-r0.x86_64",
                  "product_id": "wget-doc-1.21.4.tuxcare.els1-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/wget-doc@1.21.4.tuxcare.els1-r0?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-1.21.4.tuxcare.els1-r0.x86_64",
                "product": {
                  "name": "wget-1.21.4.tuxcare.els1-r0.x86_64",
                  "product_id": "wget-1.21.4.tuxcare.els1-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/wget@1.21.4.tuxcare.els1-r0?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-doc-1.21.4.tuxcare.els1-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:wget-doc-1.21.4.tuxcare.els1-r0.x86_64"
        },
        "product_reference": "wget-doc-1.21.4.tuxcare.els1-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-doc-1.21.4-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:wget-doc-1.21.4-r0.x86_64"
        },
        "product_reference": "wget-doc-1.21.4-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-1.21.4.tuxcare.els1-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:wget-1.21.4.tuxcare.els1-r0.x86_64"
        },
        "product_reference": "wget-1.21.4.tuxcare.els1-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-1.21.4-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:wget-1.21.4-r0.x86_64"
        },
        "product_reference": "wget-1.21.4-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2018-0494",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \\r\\n sequence in a continuation line.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Alpine-Linux-3.18:wget-1.21.4-r0.x86_64",
          "Alpine-Linux-3.18:wget-1.21.4.tuxcare.els1-r0.x86_64",
          "Alpine-Linux-3.18:wget-doc-1.21.4-r0.x86_64",
          "Alpine-Linux-3.18:wget-doc-1.21.4.tuxcare.els1-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2018-0494"
        },
        {
          "category": "external",
          "summary": "http://www.securityfocus.com/bid/104129",
          "url": "http://www.securityfocus.com/bid/104129"
        },
        {
          "category": "external",
          "summary": "http://www.securitytracker.com/id/1040838",
          "url": "http://www.securitytracker.com/id/1040838"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2018:3052",
          "url": "https://access.redhat.com/errata/RHSA-2018:3052"
        },
        {
          "category": "external",
          "summary": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cd",
          "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cd"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2018/05/msg00006.html",
          "url": "https://lists.debian.org/debian-lts-announce/2018/05/msg00006.html"
        },
        {
          "category": "external",
          "summary": "https://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.html",
          "url": "https://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.html"
        },
        {
          "category": "external",
          "summary": "https://savannah.gnu.org/bugs/?53763",
          "url": "https://savannah.gnu.org/bugs/?53763"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/201806-01",
          "url": "https://security.gentoo.org/glsa/201806-01"
        },
        {
          "category": "external",
          "summary": "https://sintonen.fi/advisories/gnu-wget-cookie-injection.txt",
          "url": "https://sintonen.fi/advisories/gnu-wget-cookie-injection.txt"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3643-1/",
          "url": "https://usn.ubuntu.com/3643-1/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/3643-2/",
          "url": "https://usn.ubuntu.com/3643-2/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2018/dsa-4195",
          "url": "https://www.debian.org/security/2018/dsa-4195"
        },
        {
          "category": "external",
          "summary": "https://www.exploit-db.com/exploits/44601/",
          "url": "https://www.exploit-db.com/exploits/44601/"
        }
      ],
      "release_date": "2018-05-06T22:29:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-05-27T18:01:14.875516Z",
          "details": "CVE‑2018‑0494 is a client‑side cookie‑poisoning bug in Wget (<1.19.5) that only applies when cookie persistence and reuse are explicitly enabled (e.g., using --save-cookies and --load-cookies) and the user fetches content from an attacker‑controlled server before making subsequent requests with the same cookie jar. Persistent cookie storage is disabled by default, the flaw offers no code execution or privilege escalation, and its effect is limited to altering HTTP cookies (no confidentiality or availability impact). In centrally managed server/VM contexts where Wget is used for non‑interactive file retrieval without persistent cookies, this is operationally low risk and can be safely deprioritized.",
          "product_ids": [
            "Alpine-Linux-3.18:wget-1.21.4-r0.x86_64",
            "Alpine-Linux-3.18:wget-1.21.4.tuxcare.els1-r0.x86_64",
            "Alpine-Linux-3.18:wget-doc-1.21.4-r0.x86_64",
            "Alpine-Linux-3.18:wget-doc-1.21.4.tuxcare.els1-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "MEDIUM",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.0"
          },
          "products": [
            "Alpine-Linux-3.18:wget-1.21.4-r0.x86_64",
            "Alpine-Linux-3.18:wget-1.21.4.tuxcare.els1-r0.x86_64",
            "Alpine-Linux-3.18:wget-doc-1.21.4-r0.x86_64",
            "Alpine-Linux-3.18:wget-doc-1.21.4.tuxcare.els1-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}