W3M Malformed MIME Header Buffer Overflow Vulnerability
BID:2895
Info
W3M Malformed MIME Header Buffer Overflow Vulnerability
| Bugtraq ID: | 2895 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2001 12:00AM |
| Updated: | Jun 19 2001 12:00AM |
| Credit: | Published in an SNS Advisory on June 19, 2001. |
| Vulnerable: |
W3M W3M 0.2.1 W3M W3M 0.2 W3M W3M 0.1.10 W3M W3M 0.1.9 W3M W3M 0.1.8 W3M W3M 0.1.7 W3M W3M 0.1.6 W3M W3M 0.1.4 W3M W3M 0.1.3 |
| Not Vulnerable: | |
Discussion
W3M Malformed MIME Header Buffer Overflow Vulnerability
W3M is a pager/text-based WWW browser similiar to lynx.
A buffer overflow vulnerability exists in the 'w3m' client program. The overflow occurs when a base64-encoded string exceeding approximately 32 characters in length is received in a MIME header field. As a result, it may be possible for a malicious remote server to execute arbitrary code on a user's system.
W3M is a pager/text-based WWW browser similiar to lynx.
A buffer overflow vulnerability exists in the 'w3m' client program. The overflow occurs when a base64-encoded string exceeding approximately 32 characters in length is received in a MIME header field. As a result, it may be possible for a malicious remote server to execute arbitrary code on a user's system.
Solution / Fix
W3M Malformed MIME Header Buffer Overflow Vulnerability
Solution:
Source code patches that rectify this issue were posted to the w3m developers' mailing list. Links to the archive of these posts can be found in the references section.
W3M W3M 0.1.10
W3M W3M 0.1.9
W3M W3M 0.2.1
Solution:
Source code patches that rectify this issue were posted to the w3m developers' mailing list. Links to the archive of these posts can be found in the references section.
W3M W3M 0.1.10
-
Conectiva 6.0 i386 w3m-0.2.1-4U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/SRPMS/w3m-0.2.1-4U60_1cl.i386. rpm -
Debian 2.2 alpha w3m-ssl_0.1.10+0.1.11pre+kokb23-4_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/w3m- ssl_0.1.10+0.1.11pre+kokb23-4_alpha.deb -
Debian 2.2 alpha w3m_0.1.10+0.1.11pre+kokb23-4_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/w3m_ 0.1.10+0.1.11pre+kokb23-4_alpha.deb -
Debian 2.2 arm w3m-ssl_0.1.10+0.1.11pre+kokb23-4_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/w3m-ss l_0.1.10+0.1.11pre+kokb23-4_arm.deb -
Debian 2.2 arm w3m_0.1.10+0.1.11pre+kokb23-4_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/w3m_0. 1.10+0.1.11pre+kokb23-4_arm.deb -
Debian 2.2 i386 w3m-ssl_0.1.10+0.1.11pre+kokb23-4_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/w3m-s sl_0.1.10+0.1.11pre+kokb23-4_i386.deb -
Debian 2.2 i386 w3m_0.1.10+0.1.11pre+kokb23-4_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/w3m_0 .1.10+0.1.11pre+kokb23-4_i386.deb -
Debian 2.2 sparc w3m-ssl_0.1.10+0.1.11pre+kokb23-4_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/w3m- ssl_0.1.10+0.1.11pre+kokb23-4_sparc.deb -
Debian 2.2 sparc w3m_0.1.10+0.1.11pre+kokb23-4_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/w3m_ 0.1.10+0.1.11pre+kokb23-4_sparc.deb
W3M W3M 0.1.9
-
Conectiva 5.0 i386 w3m-0.2.1-4U50_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/SRPMS/w3m-0.2.1-4U50_1cl.i386. rpm -
Conectiva 5.1 i386 w3m-0.2.1-4U51_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/SRPMS/w3m-0.2.1-4U51_1cl.i386. rpm
W3M W3M 0.2.1
-
Conectiva 7.0 i386 w3m-0.2.1-4U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/SRPMS/w3m-0.2.1-4U70_1cl.i386. rpm