CVE Vulnerabilities

CVE-2018-6196

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 25, 2018 | Modified: Dec 29, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
LOW

w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
W3m Tats * 0.5.3 (including)
W3m Ubuntu artful *
W3m Ubuntu devel *
W3m Ubuntu trusty *
W3m Ubuntu upstream *
W3m Ubuntu xenial *

References