CVE-2022-38223

HIGH

w3m <0.5.3 - Buffer Overflow

Title source: llm
STIX 2.1

Description

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 33.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (3)
fedoraproject/fedora 36
fedoraproject/fedora 37
tats/w3m 0.5.3
Published Aug 15, 2022
Tracked Since Feb 18, 2026