Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade w3m | Jul 30, 2024 | Dec 27, 2006 |
| Freebsd | — | Upgrade w3m-imgUpgrade ja-w3m-imgUpgrade ja-w3mUpgrade w3m-m17n-imgUpgrade w3m-m17nUpgrade w3m | Dec 10, 2025 | Jan 3, 2007 |
| Gentoo Linux | — | Upgrade www-client/w3m. | Oct 30, 2017 | Dec 27, 2006 |
| Suse | — | Upgrade w3m-inline-imageUpgrade w3m | Feb 17, 2015 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub