VDB

DEBIAN-CVE-2023-4255

DEBIAN-CVE-2023-4255 PUBLISHED CVSS 5.5 MEDIUM

An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:13w3m0, 0, 0
Debian:12w3m0.5.3+git20230121-2.2, 0.5.3+git20230121-2.3, 0.5.3+git20230121
Debian:11w3m*, *, 0
Debian:14w3m0, 0, 0

Timeline

  • Dec 21, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›