CVE-2018-6196

Name
CVE-2018-6196
Description
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/tats/w3m/issues/88
Patch https://github.com/tats/w3m/commit/8354763b90490d4105695df52674d0fcef823e92
Third Party Advisory https://usn.ubuntu.com/3555-2/
Third Party Advisory https://usn.ubuntu.com/3555-1/
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00028.html
MLIST https://lists.debian.org/debian-lts-announce/2020/04/msg00025.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:w3m_project:w3m:*:*:*:*:*:*:*:* w3m >= None <= 0.5.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
w3m edge-main 0.5.3_git20241203-r0 None fixed
w3m edge-main 0.5.3.20180125-r0 None fixed
w3m edge-community 0.5.3_git20241203-r0 Celeste <cielesti@protonmail.com> fixed
w3m edge-community 0.5.3.20180125-r0 None fixed
w3m 3.22-community 0.5.3_git20241203-r0 None fixed
w3m 3.21-community 0.5.3.20180125-r0 None fixed
w3m 3.20-community 0.5.3.20180125-r0 None fixed
w3m 3.19-community 0.5.3.20180125-r0 None fixed
w3m 3.18-community 0.5.3.20180125-r0 None fixed
w3m 3.17-community 0.5.3.20180125-r0 None fixed