CVE-2016-9436: Input Validation
Published Jan 20, 2017
·Updated
parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.
Affected Software
4 affected components
openSUSE Leap=42.2
Opensuse Project Leap=42.1
W3m Project W3m<=0.5.3\+git20160718
tats w3m<=0.5.3\+git20160718
Remediation
Patch Available
Patch Available
Event History
Jan 20, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9436?
The severity of CVE-2016-9436 is typically considered medium due to the potential for application crashes.
2
How do I fix CVE-2016-9436?
To fix CVE-2016-9436, upgrade to w3m version 0.5.3+git20161009 or later.
3
What software is affected by CVE-2016-9436?
CVE-2016-9436 affects w3m versions up to and including 0.5.3+git20160718 on specific openSUSE versions.
4
What is the impact of CVE-2016-9436?
The impact of CVE-2016-9436 is that it can allow remote attackers to crash the w3m application.
5
Is CVE-2016-9436 a critical vulnerability?
CVE-2016-9436 is not classified as critical, as it primarily leads to application denial of service.