Lucene search

K
cve[email protected]CVE-2023-38252
HistoryJul 14, 2023 - 6:15 p.m.

CVE-2023-38252

2023-07-1418:15:10
CWE-125
web.nvd.nist.gov
73
cve-2023-38252
w3m
strnew_size
str.c
denial of service
html file

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%

An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

Affected configurations

NVD
Node
tatsw3mMatch0.5.3\+git20230121
Node
fedoraprojectextra_packages_for_enterprise_linuxMatch8.0
OR
fedoraprojectfedoraMatch38
OR
redhatenterprise_linuxMatch6.0
CPENameOperatorVersion
tats:w3mtats w3meq0.5.3+git20230121

CNA Affected

[
  {
    "vendor": "Red Hat",
    "product": "Red Hat Enterprise Linux 6",
    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
    "packageName": "w3m",
    "defaultStatus": "unknown",
    "cpes": [
      "cpe:/o:redhat:enterprise_linux:6"
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

5.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.2%