PT-2002-3154 · Debian · W3M
Published
1970-01-01
·
Updated
2016-10-18
·
CVE-2002-1348
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
w3m versions prior to 0.3.2.2
Description
The issue concerns multiple vulnerabilities in the w3m package of the Debian GNU/Linux operating system, which can lead to a breach of protected information confidentiality. These vulnerabilities can be exploited remotely. The problem is related to the improper escaping of HTML tags in the ALT attribute of an IMG tag, potentially allowing remote attackers to access files or cookies.
Recommendations
For versions prior to 0.3.2.2, update to version 0.3.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
W3M