Your submission was sent successfully! Close

CVE-2016-9429

Published: 11 December 2016

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

Priority

Medium

CVSS 3 base score: 8.8

Status

Package Release Status
w3m
Launchpad, Ubuntu, Debian
precise
Released (0.5.3-5ubuntu1.2)
trusty
Released (0.5.3-15ubuntu0.1)
upstream
Released (0.5.3-30)
xenial
Released (0.5.3-26ubuntu0.1)
yakkety Ignored
(reached end-of-life)
zesty Not vulnerable
(0.5.3-32)