DEBIAN-CVE-2002-1348

Source
https://security-tracker.debian.org/tracker/CVE-2002-1348
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2002-1348.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2002-1348
Upstream
Published
2003-02-19T05:00:00Z
Modified
2025-09-24T23:47:05.623242Z
Summary
[none]
Details

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

References

Affected packages

Debian:11 / w3m

Package

Name
w3m
Purl
pkg:deb/debian/w3m?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / w3m

Package

Name
w3m
Purl
pkg:deb/debian/w3m?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / w3m

Package

Name
w3m
Purl
pkg:deb/debian/w3m?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / w3m

Package

Name
w3m
Purl
pkg:deb/debian/w3m?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}