First published: Thu Jul 13 2023(Updated: )
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tats W3m | =0.5.3\+git20230121 | |
Fedoraproject Extra Packages For Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =38 | |
Redhat Enterprise Linux | =6.0 | |
W3m Project W3m | =0.5.3\+git20230121 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38253 is an out-of-bounds read flaw in w3m, which may allow an attacker to cause a denial of service through a crafted HTML file.
The severity of CVE-2023-38253 is medium, with a severity value of 5.5.
CVE-2023-38253 affects versions of w3m up to and including 0.5.3+git20230121.
To fix CVE-2023-38253, update w3m to a version higher than 0.5.3+git20230121.
For more information about CVE-2023-38253, you can refer to the following references: [1] [2] [3].