Back to search
CVE-2016-9422
Published: Dec 12, 2016
Modified: Nov 14, 2024
PUBLISHED
Description
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of table span, which allows remote attackers to cause a denial of service (stack and/or heap buffer overflow) and possibly execute arbitrary code via a crafted HTML page.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
GLSA-201701-08
vendor-advisory
x_refsource_GENTOO
https://github.com/tats/w3m/blob/master/ChangeLog
x_refsource_CONFIRM
https://github.com/tats/w3m/issues/8
x_refsource_CONFIRM
94407
vdb-entry
x_refsource_BID
[oss-security] 20161118 Re: CVE request: w3m - multiple vulnerabilities
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now