CVE-2005-2929: High severity university of kansas lynx vulnerability
Published Nov 18, 2005
·Updated
Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.
Affected Software
3 affected components
University Of Kansas Lynx=2.8.6
University Of Kansas Lynx=2.8.6_dev13
University Of Kansas Lynx=2.8.5
Remediation
Event History
Nov 18, 2005
CVE Published
06:03 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2929?
CVE-2005-2929 has a moderate severity rating due to its potential for remote exploitation.
2
How do I fix CVE-2005-2929?
To fix CVE-2005-2929, upgrade Lynx to version 2.8.6 or later where the issue has been addressed.
3
What versions are affected by CVE-2005-2929?
CVE-2005-2929 affects Lynx versions prior to 2.8.6, specifically 2.8.5 and 2.8.6_dev13.
4
Can CVE-2005-2929 be exploited remotely?
Yes, CVE-2005-2929 can be exploited by remote attackers due to improper restrictions in certain link types.
5
What specific links are associated with CVE-2005-2929?
The links associated with CVE-2005-2929 include lynxcgi:, lynxexec, and lynxprog, which allow command execution.