MEDIUM
W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)
Published Dec 21, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.32%
Description
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.
Affected products
-
-
- Vendor n/a Product W3m Defaultaffected
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Fedora | Extra Packages for Enterprise Linux | affected |
| |||
| Fedora | Fedora | affected |
| |||
| n/a | W3m | affected |
|
Configuration 1
Configuration 2
OR
- 8.0
- 39
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://bugzilla.redhat.com/show_bug.cgi?id=2255207 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54126 Advisory
- https://github.com/tats/w3m/commit/edc602651c506aeeb60544b55534dd1722a340d3 Patch
- https://github.com/tats/w3m/issues/268 ExploitIssue TrackingPatch
- https://github.com/tats/w3m/pull/273 Issue TrackingPatch
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AULOBQJLXE2KCT5UVQMKGEFL4GFIAOED/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKFZQUK7FPWWJQYICDZZ4YWIPUPQ2D3R/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TODROGVCWZ435HQIZE6ARQC5LPQLIA5C/
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 21, 2023
Updated Feb 13, 2025
Reserved Aug 8, 2023
Link CVE-2023-4255
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2023-54126 Assigner redhat
Published Dec 21, 2023
Updated Feb 13, 2025
Exploited since n/a
Link EUVD-2023-54126