7.8
CVSSv3

CVE-2022-38223

Published: 15/08/2022 Updated: 27/03/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an malicious user to cause Denial of Service or possibly have unspecified other impact.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tats w3m 0.5.3

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1019599 w3m: CVE-2022-38223 Package: src:w3m; Maintainer for src:w3m is Tatsuya Kinoshita <tats@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 12 Sep 2022 20:39:11 UTC Severity: important Tags: security, upstream Forwarded to githubcom/tats/w3m/issues/2 ...
There is an out-of-bounds write in checkType located in etcc in w3m 053 It can be triggered by sending a crafted HTML file to the w3m binary It allows an attacker to cause Denial of Service or possibly have unspecified other impact ...