PT-2022-24295 · W3M+5 · W3M+5

Han Zheng

·

Published

2022-08-15

·

Updated

2025-11-04

·

CVE-2022-38223

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions w3m version 0.5.3
Description The issue is an out-of-bounds write in the checkType function located in etc.c. It can be triggered by sending a crafted HTML file to the w3m binary, allowing an attacker to cause Denial of Service or possibly have unspecified other impact.
Recommendations For w3m version 0.5.3, consider disabling the checkType function as a temporary workaround until a patch is available. Restrict access to the etc.c module to minimize the risk of exploitation. Avoid using crafted HTML files with the w3m binary until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12040
CVE-2022-38223
DLA-3541-1
MGASA-2023-0006
OPENSUSE-SU-2023_0065-1
OPENSUSE-SU-2024:12612-1
SUSE-SU-2023:0065-1
SUSE-SU-2023:0066-1
SUSE-SU-2023_0065-1
SUSE-SU-2023_0066-1
USN-5796-1
USN-5796-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
W3M