The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.
{ "vanir_signatures": [ { "source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd", "deprecated": false, "signature_version": "v1", "digest": { "line_hashes": [ "311004745453435617756753801353359150057", "143134225384708127344576683335910472673", "186384755597943013168483540501107179659", "112398006071132182438373256047756762888" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2016-9435-2fda5057", "target": { "file": "file.c" } }, { "source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd", "deprecated": false, "signature_version": "v1", "digest": { "line_hashes": [ "104395104491150999346745860766298117160", "22387227991403213856454022304549452974", "309193199931375910465849400156799792841" ], "threshold": 0.9 }, "signature_type": "Line", "id": "CVE-2016-9435-79107265", "target": { "file": "parsetagx.c" } }, { "source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd", "deprecated": false, "signature_version": "v1", "digest": { "function_hash": "4987390351755194380299389707932098436", "length": 25115.0 }, "signature_type": "Function", "id": "CVE-2016-9435-986b439c", "target": { "file": "file.c", "function": "HTMLtagproc1" } }, { "source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd", "deprecated": false, "signature_version": "v1", "digest": { "function_hash": "78877202036832609142144252743261376164", "length": 3604.0 }, "signature_type": "Function", "id": "CVE-2016-9435-e6ec55a9", "target": { "file": "parsetagx.c", "function": "parse_tag" } } ] }