Back

HIGH

lynx: remote arbitrary command execution via a crafted lynxcgi: URL

Published Oct 22, 2008

Description

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 22, 2008
Updated Aug 7, 2024
Reserved Oct 22, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 9, 2008