{"id":"MGASA-2024-0105","summary":"Updated w3m packages fix security vulnerabilities","details":"An out-of-bounds read flaw was found in w3m, in the Strnew_size function\nin Str.c. This issue may allow an attacker to cause a denial of service\nthrough a crafted HTML file. (CVE-2023-38252)\nAn out-of-bounds read flaw was found in w3m, in the growbuf_to_Str\nfunction in indep.c. This issue may allow an attacker to cause a denial\nof service through a crafted HTML file. (CVE-2023-38253)\nAn out-of-bounds write issue has been discovered in the backspace\nhandling of the checkType() function in etc.c within the W3M\napplication. This vulnerability is triggered by supplying a specially\ncrafted HTML file to the w3m binary. Exploitation of this flaw could\nlead to application crashes, resulting in a denial of service condition.\n(CVE-2023-4255)\n","modified":"2026-04-16T04:42:54.700418957Z","published":"2024-04-01T19:50:27Z","upstream":["CVE-2023-38252","CVE-2023-38253","CVE-2023-4255"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0105.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33027"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKFZQUK7FPWWJQYICDZZ4YWIPUPQ2D3R/"}],"affected":[{"package":{"name":"w3m","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/w3m?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.3-13.git20230121.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0105.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}