{"id":"SUSE-SU-2023:4439-1","summary":"Security update for w3m","details":"This update for w3m fixes the following issues:\n\n- Update to version 0.5.3+git20230121\n- CVE-2023-38252: Fixed an out-of-bounds write in function Strnew_size that allows attackers to cause a denial of service via a crafted HTML file. (bsc#1213324)\n- CVE-2023-38253: Fixed an out-of-bounds write in function growbuf_to_Str that allows attackers to cause a denial of service via a crafted HTML file. (bsc#1213323)\n","modified":"2026-03-11T07:25:14.481915Z","published":"2023-11-14T12:43:47Z","related":["CVE-2023-38252","CVE-2023-38253"],"upstream":["CVE-2023-38252","CVE-2023-38253"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234439-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213323"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213324"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-38252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-38253"}],"affected":[{"package":{"name":"w3m","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP4","purl":"pkg:rpm/suse/w3m&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.3+git20230121-150000.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"w3m":"0.5.3+git20230121-150000.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4439-1.json"}},{"package":{"name":"w3m","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/w3m&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.3+git20230121-150000.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"w3m":"0.5.3+git20230121-150000.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4439-1.json"}},{"package":{"name":"w3m","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/w3m&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.3+git20230121-150000.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"w3m-inline-image":"0.5.3+git20230121-150000.3.6.1","w3m":"0.5.3+git20230121-150000.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4439-1.json"}},{"package":{"name":"w3m","ecosystem":"openSUSE:Leap 15.5","purl":"pkg:rpm/opensuse/w3m&distro=openSUSE%20Leap%2015.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.3+git20230121-150000.3.6.1"}]}],"ecosystem_specific":{"binaries":[{"w3m-inline-image":"0.5.3+git20230121-150000.3.6.1","w3m":"0.5.3+git20230121-150000.3.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4439-1.json"}}],"schema_version":"1.7.5"}