PT-2018-17403 · W3M+3 · W3M+3

Tatsuya Kinoshita

·

Publicado

2018-01-24

·

Atualizado

2024-06-15

·

CVE-2018-6198

CVSS v3.1

4.7

Média

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions w3m versions prior to 0.5.3
Description The issue arises from improper handling of temporary files when the ~/.w3m directory is unwritable. This allows a local attacker to potentially craft a symlink attack, enabling them to overwrite arbitrary files.
Recommendations For versions prior to 0.5.3, update to version 0.5.3 or later to resolve the issue.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-3081
ALT-PU-2020-3099
CVE-2018-6198
MGASA-2018-0312
OPENSUSE-SU-2019_1142-1
OPENSUSE-SU-2024:11504-1
SUSE-SU-2019:0776-1
USN-3555-1
USN-3555-2

Produtos afetados

Alt Linux
Suse
Ubuntu
W3M