Description
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-3555-1 | w3m vulnerabilities |
Ubuntu USN |
USN-3555-2 | w3m vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T05:54:53.173Z
Reserved: 2018-01-24T00:00:00.000Z
Link: CVE-2018-6198
No data.
Status : Modified
Published: 2018-01-25T03:29:00.697
Modified: 2024-11-21T04:10:16.773
Link: CVE-2018-6198
OpenCVE Enrichment
No data.
Ubuntu USN