Denial of service in w3m - CVE-2018-6196
Published: February 5, 2018
Vulnerability identifier: #VU10373
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6196
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to the feed_table_block_tag function in table.c does not prevent a negative indent value. A remote attacker can trigger an infinite recursion flaw in HTMLlineproc0 and cause the service to crash.
The weakness exists due to the feed_table_block_tag function in table.c does not prevent a negative indent value. A remote attacker can trigger an infinite recursion flaw in HTMLlineproc0 and cause the service to crash.
Affected software
w3m
Fedora
Ubuntu
Opensuse
w3m
Fedora
Ubuntu
Opensuse
w3m
How to mitigate CVE-2018-6196
Install update from vendor's website.
w3m - addressed in versions 0.5.3-36.git20180125.el7, 0.5.3-36.git20180125.fc27