First published: Mon Aug 15 2022(Updated: )
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tats W3m | =0.5.3 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
W3m Project W3m | =0.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38223 is a vulnerability in w3m 0.5.3 that allows an attacker to trigger an out-of-bounds write in the 'checkType' function, potentially causing a Denial of Service or other unspecified impact.
CVE-2022-38223 can be triggered by sending a crafted HTML file to the w3m binary.
CVE-2022-38223 has a severity score of 7.8, which is considered high.
The vulnerability affects w3m 0.5.3, as well as Fedora 36 and Fedora 37.
To fix CVE-2022-38223, update to a version of w3m that is not affected by the vulnerability, and ensure any affected Fedora systems are updated to a patched version.