There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3541-1 w3m security update
Ubuntu USN Ubuntu USN USN-5796-1 w3m vulnerability
Ubuntu USN Ubuntu USN USN-5796-2 w3m vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T10:45:52.952Z

Reserved: 2022-08-15T00:00:00

Link: CVE-2022-38223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-15T11:21:43.557

Modified: 2024-11-21T07:16:05.223

Link: CVE-2022-38223

cve-icon Redhat

Severity : Important

Publid Date: 2022-08-15T00:00:00Z

Links: CVE-2022-38223 - Bugzilla

cve-icon OpenCVE Enrichment

No data.