Out-of-bounds write in w3m - CVE-2023-4255

 

Out-of-bounds write in w3m - CVE-2023-4255

Published: January 2, 2024


Vulnerability identifier: #VU84908
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4255
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing untrusted input within the checkType() function in etc.c. A remote attacker can create a specially crafted HTML file, trick the victim into opening it using the affected software, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

w3m
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Fedora
Ubuntu
w3m (Ubuntu package)
w3m-debuginfo
w3m
w3m-debugsource
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2023-4255

Install updates from vendor's website.

w3m (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 0.5.3+git20210102-6ubuntu0.2, 0.5.3+git20230121-2ubuntu0.23.04.1, 0.5.3+git20230121-2ubuntu0.23.10.1, 0.5.3-37ubuntu0.2
w3m-debuginfo - update to 0.5.3.git20161120-161.9.1
w3m - update to 0.5.3.git20161120-161.9.1
w3m-debugsource - update to 0.5.3.git20161120-161.9.1
w3m - addressed in versions 0.5.3-63.git20230121.el7, 0.5.3-63.git20230121.el8, 0.5.3-63.git20230121.el9, 0.5.3-63.git20230121.fc38, 0.5.3-63.git20230121.fc39, 0.5.3-63.git20230121.fc40
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3

External References

Related Security Bulletins