{"id":"CVE-2023-4255","summary":"W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)","details":"An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.","modified":"2026-08-12T14:51:01.061919Z","published":"2023-12-21T16:08:39.691Z","related":["SUSE-SU-2024:0014-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4255.json","cna_assigner":"redhat","cwe_ids":["CWE-787"]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AULOBQJLXE2KCT5UVQMKGEFL4GFIAOED/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKFZQUK7FPWWJQYICDZZ4YWIPUPQ2D3R/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TODROGVCWZ435HQIZE6ARQC5LPQLIA5C/"},{"type":"WEB","url":"https://packages.fedoraproject.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4255.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4255"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2255207"},{"type":"REPORT","url":"https://github.com/tats/w3m/issues/268"},{"type":"FIX","url":"https://github.com/tats/w3m/commit/edc602651c506aeeb60544b55534dd1722a340d3"},{"type":"FIX","url":"https://github.com/tats/w3m/pull/273"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tats/w3m","events":[{"introduced":"fee038d7180e3d69276f55167a0d1da5233bc9c2"},{"fixed":"edc602651c506aeeb60544b55534dd1722a340d3"}],"database_specific":{"cpe":["cpe:2.3:a:tats:w3m:0.5.3\\+git20230121-1:*:*:*:*:*:*:*","cpe:2.3:a:tats:w3m:0.5.3\\+git20230121-2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.5.3+git20230121-1"},{"last_affected":"0.5.3+git20230121-1"},{"introduced":"0.5.3+git20230121-2"},{"last_affected":"0.5.3+git20230121-2"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.5.3+git20230121-1","0.5.3+git20230121-2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4255.json","vanir_signatures_modified":"2026-08-12T14:51:01Z","vanir_signatures":[{"digest":{"function_hash":"295724129922167229010520669919116639190","length":5123},"id":"CVE-2023-4255-6dcfb28a","signature_type":"Function","signature_version":"v1","source":"https://github.com/tats/w3m/commit/edc602651c506aeeb60544b55534dd1722a340d3","target":{"file":"etc.c","function":"checkType"},"deprecated":false},{"id":"CVE-2023-4255-dab19ff2","signature_type":"Line","signature_version":"v1","source":"https://github.com/tats/w3m/commit/edc602651c506aeeb60544b55534dd1722a340d3","target":{"file":"etc.c"},"deprecated":false,"digest":{"line_hashes":["26460203148569538143327425248504244236","57830455825382049290991589887607861603","310247818144009291104860925577274623094","13455033645732134721802913651060951318","26460203148569538143327425248504244236","290663834867585646756821739283586001902","126908091885490007136439083806724560939","288785725841290717425727131037118380981"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}