First published: Fri Jan 20 2017(Updated: )
The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =42.2 | |
openSUSE Leap | =42.1 | |
w3m | <=0.5.3\+git20160718 | |
w3m | <=0.5.3\+git20160718 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9435 has a medium severity level, primarily due to its potential to crash applications.
To fix CVE-2016-9435, update to w3m version 0.5.3+git20161009 or later.
CVE-2016-9435 affects w3m versions up to and including 0.5.3+git20160718 and specific versions of openSUSE Leap.
An attacker could exploit CVE-2016-9435 to crash the w3m application using a specially crafted HTML file.
Yes, user interaction is required as the victim must open a crafted HTML file to trigger the vulnerability.