An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade w3m | Aug 22, 2024 | Jul 14, 2023 |
| Debian | — | No solution exists | May 15, 2025 | Jul 14, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 14, 2023 |
| Suse | — | Upgrade w3mUpgrade w3m-inline-image | Nov 15, 2023 | Jul 14, 2023 |
| Ubuntu | — | Upgrade w3m (Ubuntu Pro)Upgrade w3m | Nov 22, 2024 | Jul 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub