CVE-2018-6196 describes an infinite recursion flaw in w3m through version 0.5.3, specifically within the HTMLlineproc0 function due to improper handling of negative indent values in feed_table_block_tag. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-exploitable flaw with low attack complexity that can lead to high availability impact. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and it lacks significant community discussion or media coverage, its potential to cause denial of service should be noted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.3CPE matchmatch criteria | cpe:2.3:a:tats:w3m:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.