First published: Tue Oct 03 2006(Updated: )
Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/lynx | <0:2.8.5-18.2.el4_7.1 | 0:2.8.5-18.2.el4_7.1 |
redhat/lynx | <0:2.8.5-28.1.el5_2.1 | 0:2.8.5-28.1.el5_2.1 |
Lynx | <=2.8.6 | |
Lynx | =2.8.1-dev.1 | |
Lynx | =2.8.1-dev.10 | |
Lynx | =2.8.1-dev.11 | |
Lynx | =2.8.1-dev.12 | |
Lynx | =2.8.1-dev.13 | |
Lynx | =2.8.1-dev.14 | |
Lynx | =2.8.1-dev.15 | |
Lynx | =2.8.1-dev.16 | |
Lynx | =2.8.1-dev.17 | |
Lynx | =2.8.1-dev.18 | |
Lynx | =2.8.1-dev.19 | |
Lynx | =2.8.1-dev.2 | |
Lynx | =2.8.1-dev.20 | |
Lynx | =2.8.1-dev.21 | |
Lynx | =2.8.1-dev.22 | |
Lynx | =2.8.1-dev.23 | |
Lynx | =2.8.1-dev.24 | |
Lynx | =2.8.1-dev.26 | |
Lynx | =2.8.1-dev.27 | |
Lynx | =2.8.1-dev.28 | |
Lynx | =2.8.1-dev.29 | |
Lynx | =2.8.1-dev.3 | |
Lynx | =2.8.1-dev.4 | |
Lynx | =2.8.1-dev.5 | |
Lynx | =2.8.1-dev.6 | |
Lynx | =2.8.1-dev.7 | |
Lynx | =2.8.1-dev.8 | |
Lynx | =2.8.1-dev.9 | |
Lynx | =2.8.1-pre.1 | |
Lynx | =2.8.1-pre.10 | |
Lynx | =2.8.1-pre.11 | |
Lynx | =2.8.1-pre.2 | |
Lynx | =2.8.1-pre.3 | |
Lynx | =2.8.1-pre.4 | |
Lynx | =2.8.1-pre.5 | |
Lynx | =2.8.1-pre.6 | |
Lynx | =2.8.1-pre.7 | |
Lynx | =2.8.1-pre.8 | |
Lynx | =2.8.1-pre.9 | |
Lynx | =2.8.1-rel.1 | |
Lynx | =2.8.1-rel.2 | |
Lynx | =2.8.2-dev.1 | |
Lynx | =2.8.2-dev.10 | |
Lynx | =2.8.2-dev.11 | |
Lynx | =2.8.2-dev.12 | |
Lynx | =2.8.2-dev.13 | |
Lynx | =2.8.2-dev.14 | |
Lynx | =2.8.2-dev.15 | |
Lynx | =2.8.2-dev.16 | |
Lynx | =2.8.2-dev.17 | |
Lynx | =2.8.2-dev.18 | |
Lynx | =2.8.2-dev.19 | |
Lynx | =2.8.2-dev.2 | |
Lynx | =2.8.2-dev.20 | |
Lynx | =2.8.2-dev.21 | |
Lynx | =2.8.2-dev.22 | |
Lynx | =2.8.2-dev.23 | |
Lynx | =2.8.2-dev.24 | |
Lynx | =2.8.2-dev.25 | |
Lynx | =2.8.2-dev.26 | |
Lynx | =2.8.2-dev.3 | |
Lynx | =2.8.2-dev.4 | |
Lynx | =2.8.2-dev.5 | |
Lynx | =2.8.2-dev.6 | |
Lynx | =2.8.2-dev.7 | |
Lynx | =2.8.2-dev.8 | |
Lynx | =2.8.2-dev.9 | |
Lynx | =2.8.2-pre.1 | |
Lynx | =2.8.2-pre.10 | |
Lynx | =2.8.2-pre.11 | |
Lynx | =2.8.2-pre.2 | |
Lynx | =2.8.2-pre.3 | |
Lynx | =2.8.2-pre.4 | |
Lynx | =2.8.2-pre.5 | |
Lynx | =2.8.2-pre.6 | |
Lynx | =2.8.2-pre.7 | |
Lynx | =2.8.2-pre.8 | |
Lynx | =2.8.2-pre.9 | |
Lynx | =2.8.2-rel.1 | |
Lynx | =2.8.3-dev.1 | |
Lynx | =2.8.3-dev.10 | |
Lynx | =2.8.3-dev.11 | |
Lynx | =2.8.3-dev.12 | |
Lynx | =2.8.3-dev.13 | |
Lynx | =2.8.3-dev.14 | |
Lynx | =2.8.3-dev.15 | |
Lynx | =2.8.3-dev.16 | |
Lynx | =2.8.3-dev.17 | |
Lynx | =2.8.3-dev.18 | |
Lynx | =2.8.3-dev.19 | |
Lynx | =2.8.3-dev.2 | |
Lynx | =2.8.3-dev.20 | |
Lynx | =2.8.3-dev.21 | |
Lynx | =2.8.3-dev.22 | |
Lynx | =2.8.3-dev.23 | |
Lynx | =2.8.3-dev.3 | |
Lynx | =2.8.3-dev.4 | |
Lynx | =2.8.3-dev.5 | |
Lynx | =2.8.3-dev.6 | |
Lynx | =2.8.3-dev.7 | |
Lynx | =2.8.3-dev.8 | |
Lynx | =2.8.3-dev.9 | |
Lynx | =2.8.3-pre1 | |
Lynx | =2.8.3-pre2 | |
Lynx | =2.8.3-pre3 | |
Lynx | =2.8.3-pre4 | |
Lynx | =2.8.3-pre5 | |
Lynx | =2.8.3-pre6 | |
Lynx | =2.8.3-pre7 | |
Lynx | =2.8.3-pre8 | |
Lynx | =2.8.3-rel1 | |
Lynx | =2.8.4-dev1 | |
Lynx | =2.8.4-dev10 | |
Lynx | =2.8.4-dev11 | |
Lynx | =2.8.4-dev12 | |
Lynx | =2.8.4-dev13 | |
Lynx | =2.8.4-dev14 | |
Lynx | =2.8.4-dev15 | |
Lynx | =2.8.4-dev16 | |
Lynx | =2.8.4-dev17 | |
Lynx | =2.8.4-dev18 | |
Lynx | =2.8.4-dev19 | |
Lynx | =2.8.4-dev2 | |
Lynx | =2.8.4-dev20 | |
Lynx | =2.8.4-dev21 | |
Lynx | =2.8.4-dev3 | |
Lynx | =2.8.4-dev4 | |
Lynx | =2.8.4-dev5 | |
Lynx | =2.8.4-dev6 | |
Lynx | =2.8.4-dev7 | |
Lynx | =2.8.4-dev8 | |
Lynx | =2.8.4-dev9 | |
Lynx | =2.8.4-pre.1 | |
Lynx | =2.8.4-pre.2 | |
Lynx | =2.8.4-pre.3 | |
Lynx | =2.8.4-pre.4 | |
Lynx | =2.8.4-pre.5 | |
Lynx | =2.8.4-rel.1 | |
Lynx | =2.8.5-dev.1 | |
Lynx | =2.8.5-dev.10 | |
Lynx | =2.8.5-dev.11 | |
Lynx | =2.8.5-dev.12 | |
Lynx | =2.8.5-dev.13 | |
Lynx | =2.8.5-dev.14 | |
Lynx | =2.8.5-dev.15 | |
Lynx | =2.8.5-dev.16 | |
Lynx | =2.8.5-dev.17 | |
Lynx | =2.8.5-dev.2 | |
Lynx | =2.8.5-dev.3 | |
Lynx | =2.8.5-dev.4 | |
Lynx | =2.8.5-dev.5 | |
Lynx | =2.8.5-dev.6 | |
Lynx | =2.8.5-dev.7 | |
Lynx | =2.8.5-dev.8 | |
Lynx | =2.8.5-dev.9 | |
Lynx | =2.8.5-pre.1 | |
Lynx | =2.8.5-pre.2 | |
Lynx | =2.8.5-pre.3 | |
Lynx | =2.8.5-pre.4 | |
Lynx | =2.8.5-pre.5 | |
Lynx | =2.8.5-rel.1 | |
Lynx | =2.8.6-dev1 | |
Lynx | =2.8.6-dev10 | |
Lynx | =2.8.6-dev11 | |
Lynx | =2.8.6-dev12 | |
Lynx | =2.8.6-dev13 | |
Lynx | =2.8.6-dev14 | |
Lynx | =2.8.6-dev15 | |
Lynx | =2.8.6-dev2 | |
Lynx | =2.8.6-dev3 | |
Lynx | =2.8.6-dev4 | |
Lynx | =2.8.6-dev5 | |
Lynx | =2.8.6-dev6 | |
Lynx | =2.8.6-dev7 | |
Lynx | =2.8.6-dev8 | |
Lynx | =2.8.6-dev9 | |
Lynx | =2.8.6-rel1 | |
Lynx | =2.8.6-rel2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7234 has a medium severity rating as it allows local users to execute arbitrary code.
To fix CVE-2006-7234, update Lynx to version 2.8.6rel.4 or later.
CVE-2006-7234 affects Lynx versions before 2.8.6rel.4.
CVE-2006-7234 exploits untrusted search paths by allowing malicious .mailcap and mime.types files in the working directory to execute code.
Local users on systems running vulnerable versions of Lynx are impacted by CVE-2006-7234.