Back

HIGH

lynx arbitrary command execution

Published Nov 18, 2005

Description

Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Metrics

Weaknesses (1)

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 18, 2005
Updated Aug 7, 2024
Reserved Sep 15, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Nov 11, 2005