Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Slackware 10.2: 2005-310-03 Critical: Lynx Overflow Risk

slackware
Calendar Grey November 6, 2005
Scroller Slackware
Enhance Lynx tools for Slackware to fix an overflow vulnerability resulting in potential exploit risks associated with NNTP services.
New Lynx packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix a security issue

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/lynx-2.8.5rel.5-i486-1.tgz: Upgraded to lynx-2.8.5rel.5. Fixes an issue where the handling of Asian characters when using lynx to connect to an NNTP server (is this a common use?) could result in a buffer overflow causing the execution of arbitrary code. For more details, see: https://www.cve.org/CVERecord?id=CVE-2005-3120 (* Security fix *)

Where Find New Packages

Updated package for Slackware 8.1: ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/
Updated package for Slackware 9.0: ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/
Updated package for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/
Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/
Updated package for Slackware 10.1: ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/
Updated package for Slackware 10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/
Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/

MD5 Signatures

Slackware 8.1 package: adccab862ff6c6f3e56dc5fe1c8e3f94 lynx-2.8.5rel.5-i386-1.tgz
Slackware 9.0 package: 35eff3269c1b3a3d77a42eb341e3b253 lynx-2.8.5rel.5-i386-1.tgz
Slackware 9.1 package: 7e1fbf1f8ea42b13c669efa82837f2a2 lynx-2.8.5rel.5-i486-1.tgz
Slackware 10.0 package: 7d7093b6207351bc15be3effe40d1dae lynx-2.8.5rel.5-i486-1.tgz
Slackware 10.1 package: e762a5e53b7907c4e7a865e24c892eb4 lynx-2.8.5rel.5-i486-1.tgz
Slackware 10.2 package: d8c0987fce89f89908ac0965ba6e2155 lynx-2.8.5rel.5-i486-1.tgz
Slackware -current package: e429d9138374a65a8621d8b2580e3a33 lynx-2.8.5rel.5-i486-1.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg lynx-2.8.5rel.5-i486-1.tgz