CVE-2018-6197: Null Pointer Dereference
Last updated 25 August 2025
Other sources
w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/w3mto a version that resolves this vulnerability.Fixed in 0.5.3+git20210102-6+deb11u1Fixed in 0.5.3+git20230121-2Fixed in 0.5.3+git20230121-2.1Fixed in 0.5.3+git20230121-2.3
Event History
Frequently Asked Questions
What is CVE-2018-6197?
CVE-2018-6197 is a vulnerability in the w3m web browser that allows for a NULL pointer dereference flaw in formUpdateBuffer in form.c.
How severe is CVE-2018-6197?
CVE-2018-6197 has a severity rating of high (7.5).
How can I fix CVE-2018-6197?
To fix CVE-2018-6197, update w3m to version 0.5.3-37 or later.
Which software versions are affected by CVE-2018-6197?
Versions of w3m through 0.5.3 are affected by CVE-2018-6197.
Where can I find more information about CVE-2018-6197?
You can find more information about CVE-2018-6197 at the following references: http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00028.html, http://www.securityfocus.com/bid/102846, https://github.com/tats/w3m/commit/7fdc83b0364005a0b5ed869230dd81752ba022e8