CVE-2018-6196: High severity tats w3m vulnerability
Last updated 25 August 2025
Other sources
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feedtableblocktag function in table.c does not prevent a negative indent value.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/w3mto a version that resolves this vulnerability.Fixed in 0.5.3+git20210102-6+deb11u1Fixed in 0.5.3+git20230121-2Fixed in 0.5.3+git20230121-2.1Fixed in 0.5.3+git20230121-2.3
Event History
Frequently Asked Questions
What is CVE-2018-6196?
CVE-2018-6196 is a vulnerability in the w3m software through version 0.5.3, which allows for an infinite recursion flaw in HTMLlineproc0.
How severe is CVE-2018-6196?
CVE-2018-6196 has a severity score of 7.5 (high).
Which software versions are affected by CVE-2018-6196?
w3m versions 0.5.3-37, 0.5.3-37+deb10u1, 0.5.3+git20210102-6+deb11u1, and 0.5.3+git20230121-2 are affected.
How can I fix CVE-2018-6196?
To fix CVE-2018-6196, update your w3m software to version 0.5.3-36 if you are using Ubuntu, or follow the recommended updates for your specific distribution.
Where can I find more information about CVE-2018-6196?
More information about CVE-2018-6196 can be found at the following references: [1] [2] [3].