Bug 1011271 - (CVE-2016-9424) VUL-0: CVE-2016-9424: w3m: heap write
VUL-0: CVE-2016-9424: w3m: heap write
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P3 - Medium : Major
: ---
Assigned To: Thomas Blume
Security Team bot
Depends on:
Blocks: 1011293
  Show dependency treegraph
Reported: 2016-11-21 11:58 UTC by Alexander Bergmann
Modified: 2019-12-02 15:39 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2016-11-21 11:58:27 UTC
w3m: multiple vulnerabilities

heap out of bound write due to negative array index 

Issue: https://github.com/tats/w3m/issues/12
Comment 1 Swamp Workflow Management 2016-11-21 22:58:01 UTC
bugbot adjusting priority
Comment 2 Alexander Bergmann 2016-11-22 08:10:00 UTC
Upstream Fix:
Comment 3 Swamp Workflow Management 2016-12-07 19:11:25 UTC
SUSE-SU-2016:3046-1: An update that fixes 28 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1011269,1011270,1011271,1011272,1011283,1011284,1011285,1011286,1011287,1011288,1011289,1011290,1011291,1011292,1011293,1012020,1012021,1012022,1012023,1012024,1012025,1012026,1012027,1012028,1012029,1012030,1012031,1012032
CVE References: CVE-2010-2074,CVE-2016-9422,CVE-2016-9423,CVE-2016-9424,CVE-2016-9425,CVE-2016-9434,CVE-2016-9435,CVE-2016-9436,CVE-2016-9437,CVE-2016-9438,CVE-2016-9439,CVE-2016-9440,CVE-2016-9441,CVE-2016-9442,CVE-2016-9443,CVE-2016-9621,CVE-2016-9622,CVE-2016-9623,CVE-2016-9624,CVE-2016-9625,CVE-2016-9626,CVE-2016-9627,CVE-2016-9628,CVE-2016-9629,CVE-2016-9630,CVE-2016-9631,CVE-2016-9632,CVE-2016-9633
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    w3m-0.5.3.git20161120-4.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    w3m-0.5.3.git20161120-4.1
Comment 4 Thomas Blume 2017-05-11 07:46:13 UTC
Comment 5 Marcus Meissner 2017-09-06 11:37:55 UTC
(This issue was also fixed for SLE12 , just the CVE was not mentioned in the w3m.changes. I have cross checked this against the testcase.)