w3m-0.5.1-17.AXS3

エラータID: AXSA:2010-392:01

Release date: 
Wednesday, July 28, 2010 - 14:21
Subject: 
w3m-0.5.1-17.AXS3
Affected Channels: 
Asianux Server 3 for x86
Asianux Server 3 for x86_64
Severity: 
High
Description: 

The w3m program is a pager (or text file viewer) that can also be used as a text-mode Web browser. W3m features include the following: when reading an HTML document, you can follow links and view images using an external image viewer; its internet message mode determines the type of document from the header; if the Content-Type field of the document is text/html, the document is displayed as an HTML document; you can change a URL description like 'http://hogege.net' in plain text into a link to that URL.
If you want to display the inline images on w3m, you need to install w3m-img package as well.
Security issues fixed with this release:
CVE-2010-2074
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. w3m-0.5.1-17.AXS3.src.rpm
    MD5: e7c38e79f83bd335a93aeb13a8bb7b5e
    SHA-256: 73f813ef96ae2d2d121f676534a364210831df87c7d957e1a85ddaf0f0e816a2
    Size: 2.44 MB

Asianux Server 3 for x86
  1. w3m-0.5.1-17.AXS3.i386.rpm
    MD5: 049a3a378526f2ed8ebe4d37c8f6c1d0
    SHA-256: aa233c07017f90e095cdd31e714ec7c2c53c680fcc37893e7a72374802aae704
    Size: 1.10 MB

Asianux Server 3 for x86_64
  1. w3m-0.5.1-17.AXS3.x86_64.rpm
    MD5: b158fa34a93f8d18be558aaa84f39860
    SHA-256: 34e1445e7cd456125694cbd9df5e1c86502745cc11e81981bd803220b002e6ef
    Size: 1.13 MB