Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA 1085-1 Critical: Lynx-ssl Remote Exploit Detail

debian
Calendar Grey June 1, 2006
Debian Logo
Updates to Lynx-ssl in Debian mitigate vulnerabilities: Resolving remote exploitation and numerous concerns for improved protection.
Updated package.

Summary


CVE-2004-1617

Michal Zalewski discovered that lynx is not able to grok invalid
HTML including a TEXTAREA tag with a large COLS value and a large
tag name in an element that is not terminated, and loops forever
trying to render the broken HTML.

CAN-2005-3120

Ulf H�rnhammar discovered a buffer overflow that can be remotely
exploited. During the handling of Asian characters when connecting
to an NNTP server lynx can be tricked to write past the boundary
of a buffer which can lead to the execution of arbitrary code.

For the old stable distribution (woody) these problems have been fixed in
version 2.8.5-2.5woody1.

For the stable distribution (sarge) these problems have been fixed in
version 2.8.6-9sarge1.

For the unstable distribution (sid) these problems will be fixed soon.

We recommend that you upgrade your lynx-cur package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will i...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here