Lucene search

K
cve[email protected]CVE-2006-6772
HistoryDec 27, 2006 - 11:28 p.m.

CVE-2006-6772

2006-12-2723:28:00
CWE-134
web.nvd.nist.gov
24
cve-2006-6772
w3m
format string vulnerability
ssl certificate
remote code execution

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.127 Low

EPSS

Percentile

95.5%

Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.

Affected configurations

NVD
Node
w3mw3mMatch0.5.1
CPENameOperatorVersion
w3m:w3mw3meq0.5.1

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.127 Low

EPSS

Percentile

95.5%