First published: Wed Jan 24 2018(Updated: )
w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
W3m Project W3m | <=0.5.3 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Tats W3m | <=0.5.3 | |
ubuntu/w3m | <0.5.3-34ubuntu0.1 | 0.5.3-34ubuntu0.1 |
ubuntu/w3m | <0.5.3-15ubuntu0.2 | 0.5.3-15ubuntu0.2 |
ubuntu/w3m | <0.5.3-36 | 0.5.3-36 |
ubuntu/w3m | <0.5.3-26ubuntu0.2 | 0.5.3-26ubuntu0.2 |
debian/w3m | 0.5.3+git20210102-6+deb11u1 0.5.3+git20230121-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6197 is a vulnerability in the w3m web browser that allows for a NULL pointer dereference flaw in formUpdateBuffer in form.c.
CVE-2018-6197 has a severity rating of high (7.5).
To fix CVE-2018-6197, update w3m to version 0.5.3-37 or later.
Versions of w3m through 0.5.3 are affected by CVE-2018-6197.
You can find more information about CVE-2018-6197 at the following references: http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00028.html, http://www.securityfocus.com/bid/102846, https://github.com/tats/w3m/commit/7fdc83b0364005a0b5ed869230dd81752ba022e8