CVE-2016-9435: Input Validation
Published Jan 20, 2017
·Updated
The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.
Affected Software
4 affected components
openSUSE Leap=42.2
Opensuse Project Leap=42.1
W3m Project W3m<=0.5.3\+git20160718
tats w3m<=0.5.3\+git20160718
Remediation
Patch Available
Patch Available
Event History
Jan 20, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9435?
CVE-2016-9435 has a medium severity level, primarily due to its potential to crash applications.
2
How do I fix CVE-2016-9435?
To fix CVE-2016-9435, update to w3m version 0.5.3+git20161009 or later.
3
Which software versions are affected by CVE-2016-9435?
CVE-2016-9435 affects w3m versions up to and including 0.5.3+git20160718 and specific versions of openSUSE Leap.
4
What types of attacks are possible with CVE-2016-9435?
An attacker could exploit CVE-2016-9435 to crash the w3m application using a specially crafted HTML file.
5
Is user interaction required to exploit CVE-2016-9435?
Yes, user interaction is required as the victim must open a crafted HTML file to trigger the vulnerability.