REDHAT-BUG-2255207: Medium severity w3m vulnerability
w3m has an out-of-bounds write in function checkType() in etc.c. It allows a local attacker to cause Denial of Service or possibly have unspecified other impact via a crafted HTML file. NOTE: It was introduced in the fix of CVE-2022-38223.
Affects: w3m 0.5.3+git20230129, 0.5.3+git20230121-1, 0.5.3+git20230121-2 Not Affected version: < 0.5.3+git20220429-1
https://github.com/tats/w3m/issues/268 https://github.com/tats/w3m/pull/273
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2255207?
The severity of REDHAT-BUG-2255207 is considered high due to the potential for Denial of Service and other unspecified impacts.
How do I fix REDHAT-BUG-2255207?
To fix REDHAT-BUG-2255207, update w3m to a version that addresses the out-of-bounds write vulnerability.
Which versions of w3m are affected by REDHAT-BUG-2255207?
Versions of w3m starting from 0.5.3+git20230121 up to the latest prior to the fix are affected by REDHAT-BUG-2255207.
Can REDHAT-BUG-2255207 be exploited remotely?
No, REDHAT-BUG-2255207 is a local vulnerability that requires local access to the system.
What impact can REDHAT-BUG-2255207 have on my system?
REDHAT-BUG-2255207 can lead to Denial of Service and may allow for other unspecified impacts depending on the exploit.