Solution
Please Install the Updated Packages.
Insight
The w3m program is a pager (or text file viewer) that can also be used as a text mode web browser.
It was discovered that w3m is affected by the previously published " null
prefix attack"
, caused by incorrect handling of NULL characters in X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse w3m into accepting it by mistake. (CVE-2010-2074)
All w3m users should upgrade to these updated packages, which contain a backported patch to correct this issue.
Affected
w3m on Red Hat Enterprise Linux (v. 5 server)
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2010-2074 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities