NA

CVE-2023-4255

Published: 21/12/2023 Updated: 27/03/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.

Vulnerable Product Search on Vulmon Subscribe to Product

tats w3m 0.5.3\\+git20230129

tats w3m 0.5.3\\+git20230121-1

tats w3m 0.5.3\\+git20230121-2

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1059265 w3m: CVE-2023-4255 Package: src:w3m; Maintainer for src:w3m is Tatsuya Kinoshita <tats@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 09:39:14 UTC Severity: grave Tags: security, upstream Found in version w3m/053+git20230121-2 Forwarded to ...