CVE-2016-9436 log

Source
Severity High
Remote Yes
Type Arbitrary code execution
Description
Multiple issues have been discovered related to uninitialized values for <i> and <dd> HTML elements. A missing null string termination for the tagname variable in parsetagx.c is leading to an out of bounds access.
Group Package Affected Fixed Severity Status Ticket
AVG-73 w3m 0.5.3.git20160413-1 0.5.3.git20161031-1 Critical Fixed
Date Advisory Group Package Severity Type
18 Nov 2016 ASA-201611-18 AVG-73 w3m Critical multiple issues
References
https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd
http://www.openwall.com/lists/oss-security/2016/11/18/3