ISOMAN

CVE

CVE-2018-6196

w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00028.html
  2. https://github.com/tats/w3m/commit/8354763b90490d4105695df52674d0fcef823e92
  3. https://github.com/tats/w3m/issues/88
  4. https://lists.debian.org/debian-lts-announce/2020/04/msg00025.html
  5. https://usn.ubuntu.com/3555-1/
  6. https://usn.ubuntu.com/3555-2/
  7. http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00028.html
  8. https://github.com/tats/w3m/commit/8354763b90490d4105695df52674d0fcef823e92
  9. https://github.com/tats/w3m/issues/88
  10. https://lists.debian.org/debian-lts-announce/2020/04/msg00025.html
  11. https://usn.ubuntu.com/3555-1/
  12. https://usn.ubuntu.com/3555-2/