REDHAT-BUG-2222775: Low severity w3m vulnerability
Published Jul 13, 2023
·Updated
w3m 0.5.3+git20230129 has an out-of-bounds read in function Strnewsize in Str.c. This allows attackers to cause a denial of service via a crafted HTML file.
Upstream issue:
https://github.com/tats/w3m/issues/270
Affected Software
1 affected component
tats w3m
Event History
Jul 13, 2023
Data Sourced
via Red Hat·04:50 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2222775?
The severity of REDHAT-BUG-2222775 is considered high due to its potential for causing a denial of service.
2
How do I fix REDHAT-BUG-2222775?
To fix REDHAT-BUG-2222775, you should update the w3m package to the latest version that addresses this vulnerability.
3
What causes the vulnerability REDHAT-BUG-2222775?
REDHAT-BUG-2222775 is caused by an out-of-bounds read in the Strnew_size function in the w3m code.
4
What software is affected by REDHAT-BUG-2222775?
The REDHAT-BUG-2222775 vulnerability affects the w3m software, specifically versions prior to the fix.
5
Can REDHAT-BUG-2222775 be exploited remotely?
Yes, REDHAT-BUG-2222775 can be exploited remotely via a crafted HTML file.