PT-2008-1065 · Centos+3 · Centos+3

Published

2008-10-22

·

Updated

2024-06-15

·

CVE-2008-4690

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions lynx versions 2.8.4 through 2.8.5 lynx version 2.8.6dev.15 and earlier
Description The issue affects the lynx package in various operating systems, including Red Hat Enterprise Linux and CentOS, allowing remote attackers to exploit multiple vulnerabilities. These vulnerabilities can lead to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely. In specific configurations where lynx is set up as a URL handler and advanced mode is enabled, attackers can execute arbitrary commands via a crafted lynxcgi: URL.
Recommendations For lynx versions 2.8.4 through 2.8.5, consider updating to a version later than 2.8.5 to mitigate the risk. For lynx version 2.8.6dev.15 and earlier, as a temporary workaround, consider disabling the advanced mode or removing the lynxcgi: handler configuration until a patch is available. Restrict access to the lynx package to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2018-1970
BDU:2015-06413
BDU:2015-06414
BDU:2015-08355
BDU:2015-08356
CVE-2008-4690
OPENSUSE-SU-2024:10329-1
RHSA-2008:0965
RHSA-2008_0965

Affected Products

Alt Linux
Centos
Red Hat
Lynx