lynx arbitrary command execution
Published Nov 18, 2005
7.5
HIGHCVSS 2.0
EPSS 4.92%
Description
Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.
Affected products
No data.
- 2.8.5
- 2.8.6
- 2.8.6_dev13
No data.
Red Hat Enterprise Linux 3
lynx-0:2.8.5-11.2
Fixed · RHSA-2005:839
Red Hat Enterprise Linux 4
lynx-0:2.8.5-18.2
Fixed · RHSA-2005:839
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | lynx-0:2.8.5-11.2 | Fixed | RHSA-2005:839 |
| Red Hat Enterprise Linux 4 | lynx-0:2.8.5-18.2 | Fixed | RHSA-2005:839 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.92% (0.04923) | 91.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.92% (0.04923) | 90.97th | v5 (v2026.06.15) |
| Mar 30, 2025 | 6.64% (0.06636) | 90.29th | v4 (v2025.03.14) |
| Mar 29, 2025 | 11.65% (0.11652) | 89.40th | v4 (v2025.03.14) |
| Mar 19, 2025 | 6.64% (0.06636) | 90.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.87% (0.04865) | 88.82th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.28% (0.01277) | 86.30th | v3 (v2023.03.01) |
| Jul 10, 2024 | 1.79% (0.01788) | 88.24th | v3 (v2023.03.01) |
| Apr 13, 2023 | 1.79% (0.01788) | 86.23th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.27% (0.01268) | 83.51th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (29)
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.7/SCOSA-2006.7.txt vendor-advisoryx_refsource_SCO
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.55/SCOSA-2005.55.txt vendor-advisoryx_refsource_SCO
- http://secunia.com/advisories/17372 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17512 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17546 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17556 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17576 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17666 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/17757 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18051 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18376 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18659 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securityreason.com/securityalert/173 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015195 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2006-035.htm x_refsource_CONFIRM
- http://www.gentoo.org/security/en/glsa/glsa-200511-09.xml vendor-advisoryx_refsource_GENTOO
- http://www.idefense.com/application/poi/display?id=338&type=vulnerabilities third-party-advisoryx_refsource_IDEFENSEPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:211 vendor-advisoryx_refsource_MANDRIVA
- http://www.openpkg.org/security/OpenPKG-SA-2005.026-lynx.html vendor-advisoryx_refsource_OPENPKG
- http://www.redhat.com/support/errata/RHSA-2005-839.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/419763/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/15395 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2005/2394 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2005-2929 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=172972 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23119 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2005-2929
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9712 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2005-2929
Change history (0)
No recorded changes yet.