Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-38223

Опубликовано: 15 авг. 2022
Источник: debian
EPSS Низкий

Описание

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
w3mfixed0.5.3+git20230121-1package
w3mfixed0.5.3+git20210102-6+deb11u1bullseyepackage

Примечания

  • https://github.com/tats/w3m/issues/242

  • Initial fix: https://github.com/tats/w3m/commit/419ca82d57c72242817b55e2eaa4cdbf6916e7fa

  • Follow-up fix: https://github.com/tats/w3m/commit/25fb402cea405b263466c627f32513d186a38ade

EPSS

Процентиль: 35%
0.00142
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

CVSS3: 7.8
redhat
больше 3 лет назад

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

CVSS3: 7.8
nvd
больше 3 лет назад

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

suse-cvrf
около 3 лет назад

Security update for w3m

suse-cvrf
около 3 лет назад

Security update for w3m

EPSS

Процентиль: 35%
0.00142
Низкий