CVE-2023-4255: W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.
Other sources
w3m has an out-of-bounds write in function checkType() in etc.c. It allows a local attacker to cause Denial of Service or possibly have unspecified other impact via a crafted HTML file. NOTE: It was introduced in the fix of CVE-2022-38223.
Affects: w3m 0.5.3+git20230129, 0.5.3+git20230121-1, 0.5.3+git20230121-2 Not Affected version: < 0.5.3+git20220429-1
https://github.com/tats/w3m/issues/268 https://github.com/tats/w3m/pull/273
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4255?
CVE-2023-4255 is classified as a high severity vulnerability due to its potential to allow an out-of-bounds write in the W3M application.
How do I fix CVE-2023-4255?
To remediate CVE-2023-4255, upgrade to the latest version of the W3M package that is not affected, specifically versions beyond 0.5.3-37.
What systems are vulnerable to CVE-2023-4255?
CVE-2023-4255 affects various versions of the W3M application on Debian and Ubuntu systems.
What is the impact of exploiting CVE-2023-4255?
Exploiting CVE-2023-4255 could lead to application crashes or arbitrary code execution due to an out-of-bounds write.
How can users identify if they are using a vulnerable version of W3M affected by CVE-2023-4255?
Users should check their W3M version; any version up to and including 0.5.3-37 is potentially vulnerable to CVE-2023-4255.