Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918564 (CVE-2023-38252, CVE-2023-38253) - www-client/w3m: multiple vulnerabilities
Summary: www-client/w3m: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2023-38252, CVE-2023-38253
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [upstream/ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-25 22:39 UTC by John Helmert III
Modified: 2023-11-25 22:39 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-25 22:39:26 UTC
CVE-2023-38252 (https://github.com/tats/w3m/issues/270):

An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

CVE-2023-38253 (https://github.com/tats/w3m/issues/271):

An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

Fixes in https://github.com/tats/w3m/commit/25fb402cea405b263466c627f32513d186a38ade from https://github.com/tats/w3m/pull/273, seemingly not in any release.