CVE-2006-6772
Summary
| CVE | CVE-2006-6772 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-27 23:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo update for w3m - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SUSE update for w3m - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVS Info for project w3m | af854a3a-2127-422b-91ae-364da2661108 | w3m.cvs.sourceforge.net | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| SourceForge.net: ERROR | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Ubuntu update for w3m - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| OpenPKG Corporation: Security: Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.openpkg.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - w3m Format String Bug in Processing Certificates May Permit Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| w3m Certificate Handling Format String Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVS Info for project w3m | af854a3a-2127-422b-91ae-364da2661108 | w3m.cvs.sourceforge.net | |
| [Full-disclosure] xss problems | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVS Info for project w3m | af854a3a-2127-422b-91ae-364da2661108 | w3m.cvs.sourceforge.net | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | |
| w3m: Format string vulnerability — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Fedora update for w3m - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | |
| W3M Browser InputAnswer Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| usn/USN-399-1 - Ubuntu: Linux for human beings | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| W3M SSL Certificate Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVS Info for project w3m | MITRE | w3m.cvs.sourceforge.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-03-14 | Mark J Cox | Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch. |
There are currently no legacy QID mappings associated with this CVE.