There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade w3m | Aug 22, 2024 | Aug 15, 2022 |
| Debian | — | Upgrade w3m | Aug 28, 2023 | Aug 15, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 15, 2022 |
| Suse | — | suse-upgrade-w3msuse-upgrade-w3m-inline-image | Jan 12, 2023 | Aug 15, 2022 |
| Ubuntu | ubuntu-pro-upgrade-w3mubuntu-upgrade-w3m | Jan 10, 2023 | Aug 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub