Description
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3541-1 | w3m security update |
Ubuntu USN |
USN-5796-1 | w3m vulnerability |
Ubuntu USN |
USN-5796-2 | w3m vulnerability |
References
History
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T18:14:23.129Z
Reserved: 2022-08-15T00:00:00.000Z
Link: CVE-2022-38223
No data.
Status : Modified
Published: 2022-08-15T11:21:43.557
Modified: 2025-11-04T19:15:41.110
Link: CVE-2022-38223
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Ubuntu USN