parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.
[
{
"id": "CVE-2016-9436-2fda5057",
"digest": {
"line_hashes": [
"311004745453435617756753801353359150057",
"143134225384708127344576683335910472673",
"186384755597943013168483540501107179659",
"112398006071132182438373256047756762888"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "file.c"
},
"source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd",
"signature_type": "Line",
"signature_version": "v1"
},
{
"id": "CVE-2016-9436-79107265",
"digest": {
"line_hashes": [
"104395104491150999346745860766298117160",
"22387227991403213856454022304549452974",
"309193199931375910465849400156799792841"
],
"threshold": 0.9
},
"deprecated": false,
"target": {
"file": "parsetagx.c"
},
"source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd",
"signature_type": "Line",
"signature_version": "v1"
},
{
"id": "CVE-2016-9436-986b439c",
"digest": {
"length": 25115.0,
"function_hash": "4987390351755194380299389707932098436"
},
"deprecated": false,
"target": {
"file": "file.c",
"function": "HTMLtagproc1"
},
"source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd",
"signature_type": "Function",
"signature_version": "v1"
},
{
"id": "CVE-2016-9436-e6ec55a9",
"digest": {
"length": 3604.0,
"function_hash": "78877202036832609142144252743261376164"
},
"deprecated": false,
"target": {
"file": "parsetagx.c",
"function": "parse_tag"
},
"source": "https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd",
"signature_type": "Function",
"signature_version": "v1"
}
]