CVE-1999-0817: Critical severity university of kansas lynx vulnerability

Published Sep 15, 1999
·
Updated

Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.

Affected Software

2 affected componentsFixes available
University Of Kansas Lynx
Microsoft cbl2 lynx 2.9.0~dev.9-5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Lynx from your environment.

    Uninstall Lynx if it is not required to remove exposure to this behavior.

  2. Configuration

    Disable Lynx's use of external programs to handle protocols so it does not pass remote-supplied command-line parameters to external programs.

    Lynx external_protocol_handlers = disabled
  3. Configuration

    Disable handling of telnet: (and other external-protocol) URLs to prevent Lynx from invoking external telnet clients with attacker-supplied parameters.

    Lynx telnet_handler = disabled
  4. Compensating control

    Block or filter telnet and other external-protocol schemes at the network perimeter, proxy, or gateway so users cannot reach or cause Lynx to invoke external protocol handlers.

Event History

Sep 15, 1999
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Sep 4, 2025
Data Sourced
via Microsoft·02:34 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:34 AM
Affected Software
Updated
via Microsoft·02:34 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-1999-0817?

CVE-1999-0817 has a moderate severity rating due to its potential for abuse by remote attackers.

2

How do I fix CVE-1999-0817?

To fix CVE-1999-0817, you should upgrade to the latest version of Lynx that addresses this vulnerability.

3

Which versions of Lynx are affected by CVE-1999-0817?

CVE-1999-0817 can affect various versions of Lynx, so it's important to check the specific version in use.

4

What type of attack is possible with CVE-1999-0817?

CVE-1999-0817 allows remote attackers to exploit command-line parameters when Lynx calls external programs.

5

Is Lynx still a widely used browser affected by CVE-1999-0817?

While Lynx is less commonly used today, it is still found in specific environments, making CVE-1999-0817 a relevant vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203