CVE-2016-9424

Name
CVE-2016-9424
Description
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap buffer overflow crash) and possibly execute arbitrary code via a crafted HTML page.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List http://www.openwall.com/lists/oss-security/2016/11/18/3
cve@mitre.org http://www.securityfocus.com/bid/94407
Issue Tracking https://github.com/tats/w3m/blob/master/ChangeLog
Issue Tracking https://github.com/tats/w3m/issues/12
cve@mitre.org https://security.gentoo.org/glsa/201701-08

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:tats:w3m:*:*:*:*:*:*:*:* w3m >= None <= 0.5.3-30

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
w3m edge-community 0.5.3.20230718-r1 Celeste <cielesti@protonmail.com> possibly vulnerable
w3m 3.19-community 0.5.3.20230718-r1 Celeste <cielesti@protonmail.com> possibly vulnerable