MGASA-2021-0422 - Updated lynx packages fix security vulnerability Publication date: 23 Sep 2021 URL: https://advisories.mageia.org/MGASA-2021-0422.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-38165 Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. (CVE-2021-38165) References: - https://bugs.mageia.org/show_bug.cgi?id=29342 - https://www.openwall.com/lists/oss-security/2021/08/07/9 - https://www.debian.org/security/2021/dsa-4953 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38165 SRPMS: - 8/core/lynx-2.8.9-0.dev17.4.1.mga8