Mehrere Probleme in w3m
ID: | FEDORA-2018-0ad6e73ac0 |
Distribution: | Fedora |
Plattformen: | Fedora 27 |
Datum: | Do, 8. Februar 2018, 15:16 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6197
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6196 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6198 |
Applikationen: | w3m |
Originalnachricht |
|
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-0ad6e73ac0 2018-02-08 13:12:01.701356 -------------------------------------------------------------------------------- Name : w3m Product : Fedora 27 Version : 0.5.3 Release : 36.git20180125.fc27 URL : http://w3m.sourceforge.net/ Summary : A pager with Web browsing abilities Description : The w3m program is a pager (or text file viewer) that can also be used as a text-mode Web browser. W3m features include the following: when reading an HTML document, you can follow links and view images using an external image viewer; its internet message mode determines the type of document from the header; if the Content-Type field of the document is text/html, the document is displayed as an HTML document; you can change a URL description like 'http://hogege.net' in plain text into a link to that URL. If you want to display the inline images on w3m, you need to install w3m-img package as well. -------------------------------------------------------------------------------- Update Information: Rebase to latest upstream gitrev 20180125 and Security fix for CVE-2018-6196, CVE-2018-6197, CVE-2018-6198 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1539151 - CVE-2018-6197 w3m: Null pointer dereference in formUpdateBuffer in form.c https://bugzilla.redhat.com/show_bug.cgi?id=1539151 [ 2 ] Bug #1539157 - CVE-2018-6196 w3m: Infinite recursion in HTMLlineproc0 https://bugzilla.redhat.com/show_bug.cgi?id=1539157 [ 3 ] Bug #1539127 - CVE-2018-6198 w3m: insecure temporary files creation when ~/.w3m is unwritable https://bugzilla.redhat.com/show_bug.cgi?id=1539127 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade w3m' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org |