Comment 5 for bug 2029930

Revision history for this message
Mark Esler (eslerm) wrote :

Upstream will not be assigning this issue a CVE [0] and the Ubuntu Security Team does not consider this bug security relevant.

This bug is caused when calculating the download speed, but hitting an out-of-bounds on the table that contains the printable strings. It is hitting GB/s because it is, presumably, not handling the system timer resolution correctly. This is no more security relevant than any other bug that crashes wget.

@wiebe-halfgaar, thank you for raising awareness about this issue and getting it fixed upstream.

[0] https://lists.gnu.org/archive/html/bug-wget/2023-08/msg00008.html