PT-2002-3154 · Debian · W3M

Published

1970-01-01

·

Updated

2016-10-18

·

CVE-2002-1348

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions w3m versions prior to 0.3.2.2
Description The issue concerns multiple vulnerabilities in the w3m package of the Debian GNU/Linux operating system, which can lead to a breach of protected information confidentiality. These vulnerabilities can be exploited remotely. The problem is related to the improper escaping of HTML tags in the ALT attribute of an IMG tag, potentially allowing remote attackers to access files or cookies.
Recommendations For versions prior to 0.3.2.2, update to version 0.3.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02566
BDU:2015-02684
BDU:2015-02685
BDU:2015-02929
BDU:2015-03067
BDU:2015-03291
CVE-2002-1348
DSA-249
DSA-251

Affected Products

W3M