Related Vulnerabilities: CVE-2016-9435  

Multiple issues have been discovered related to uninitialized values for <i> and <dd> HTML elements. A missing PUSH_ENV(HTML_DL) call is leading to a conditional jump or move depending on an uninitialized value resulting in a stack overflow vulnerability.

Severity High

Remote Yes

Type Arbitrary code execution

Description

Multiple issues have been discovered related to uninitialized values for <i> and <dd> HTML elements. A missing PUSH_ENV(HTML_DL) call is leading to a conditional jump or move depending on an uninitialized value resulting in a stack overflow vulnerability.

AVG-73 w3m 0.5.3.git20160413-1 0.5.3.git20161031-1 Critical Fixed

18 Nov 2016 ASA-201611-18 AVG-73 w3m Critical multiple issues

https://github.com/tats/w3m/issues/16
http://www.openwall.com/lists/oss-security/2016/11/18/3