CVE-2016-9435 log

Source
Severity High
Remote Yes
Type Arbitrary code execution
Description
Multiple issues have been discovered related to uninitialized values for <i> and <dd> HTML elements. A missing PUSH_ENV(HTML_DL) call is leading to a conditional jump or move depending on an uninitialized value resulting in a stack overflow vulnerability.
Group Package Affected Fixed Severity Status Ticket
AVG-73 w3m 0.5.3.git20160413-1 0.5.3.git20161031-1 Critical Fixed
Date Advisory Group Package Severity Description
18 Nov 2016 ASA-201611-18 AVG-73 w3m Critical multiple issues
References
https://github.com/tats/w3m/issues/16
http://www.openwall.com/lists/oss-security/2016/11/18/3