There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3541-1 | w3m security update |
Ubuntu USN |
USN-5796-1 | w3m vulnerability |
Ubuntu USN |
USN-5796-2 | w3m vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T18:14:23.129Z
Reserved: 2022-08-15T00:00:00.000Z
Link: CVE-2022-38223
No data.
Status : Modified
Published: 2022-08-15T11:21:43.557
Modified: 2025-11-04T19:15:41.110
Link: CVE-2022-38223
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Ubuntu USN