Related Vulnerabilities: CVE-2016-9436  

Multiple issues have been discovered related to uninitialized values for <i> and <dd> HTML elements. A missing null string termination for the tagname variable in parsetagx.c is leading to an out of bounds access.

Severity High

Remote Yes

Type Arbitrary code execution

Description

Multiple issues have been discovered related to uninitialized values for <i> and <dd> HTML elements. A missing null string termination for the tagname variable in parsetagx.c is leading to an out of bounds access.

AVG-73 w3m 0.5.3.git20160413-1 0.5.3.git20161031-1 Critical Fixed

18 Nov 2016 ASA-201611-18 AVG-73 w3m Critical multiple issues

https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd
http://www.openwall.com/lists/oss-security/2016/11/18/3