Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-6772
Description:Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.
Test IDs: 1.3.6.1.4.1.25623.1.0.59451   1.3.6.1.4.1.25623.1.0.65332   1.3.6.1.4.1.25623.1.0.861184   1.3.6.1.4.1.25623.1.0.57966   1.3.6.1.4.1.25623.1.0.861025   1.3.6.1.4.1.25623.1.0.58039   1.3.6.1.4.1.25623.1.0.57747  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-6772
BugTraq ID: 21735
http://www.securityfocus.com/bid/21735
BugTraq ID: 24332
http://www.securityfocus.com/bid/24332
http://fedoranews.org/cms/node/2415
http://fedoranews.org/cms/node/2416
http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051457.html
http://security.gentoo.org/glsa/glsa-200701-06.xml
http://sourceforge.net/tracker/index.php?func=detail&aid=1612792&group_id=39518&atid=425439
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.044.html
http://securitytracker.com/id?1017440
http://secunia.com/advisories/23492
http://secunia.com/advisories/23588
http://secunia.com/advisories/23717
http://secunia.com/advisories/23773
http://secunia.com/advisories/23792
SuSE Security Announcement: SUSE-SA:2007:005 (Google Search)
http://www.novell.com/linux/security/advisories/2007_05_w3m.html
http://www.ubuntu.com/usn/usn-399-1
http://www.vupen.com/english/advisories/2006/5164
XForce ISS Database: w3m-certificate-format-string(31114)
https://exchange.xforce.ibmcloud.com/vulnerabilities/31114
XForce ISS Database: w3m-inputanswer-format-string(34821)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34821




© 1998-2025 E-Soft Inc. All rights reserved.