First published: Wed Oct 22 2008(Updated: )
lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lynx Lynx | =2.8.3-pre1 | |
Lynx Lynx | =2.8.1-dev.5 | |
Lynx Lynx | =2.8.5-dev.6 | |
Lynx Lynx | =2.8.1-dev.20 | |
Lynx Lynx | =2.8.2-dev.17 | |
Lynx Lynx | =2.8.6-dev5 | |
Lynx Lynx | =2.8.4-dev17 | |
Lynx Lynx | =2.8.6-dev4 | |
Lynx Lynx | =2.8.4-dev11 | |
Lynx Lynx | =2.8.4-dev10 | |
Lynx Lynx | =2.8.5-dev.3 | |
Lynx Lynx | =2.8.1-dev.7 | |
Lynx Lynx | =2.8.3-pre6 | |
Lynx Lynx | =2.8.6-dev8 | |
Lynx Lynx | =2.8.5-pre.1 | |
Lynx Lynx | =2.8.2-dev.22 | |
Lynx Lynx | =2.8.3-dev.11 | |
Lynx Lynx | =2.8.4-pre.1 | |
Lynx Lynx | =2.8.5-dev.9 | |
Lynx Lynx | =2.8.1-rel.2 | |
Lynx Lynx | =2.8.1-dev.10 | |
Lynx Lynx | =2.8.3-dev.7 | |
Lynx Lynx | =2.8.3-dev.17 | |
Lynx Lynx | =2.8.1-dev.13 | |
Lynx Lynx | =2.8.1-pre.5 | |
Lynx Lynx | =2.8.4-dev5 | |
Lynx Lynx | =2.8.4-pre.4 | |
Lynx Lynx | =2.8.6-dev14 | |
Lynx Lynx | =2.8.1-dev.15 | |
Lynx Lynx | =2.8.3-rel1 | |
Lynx Lynx | =2.8.3-pre7 | |
Lynx Lynx | =2.8.1-pre.7 | |
Lynx Lynx | =2.8.3-dev.10 | |
Lynx Lynx | =2.8.2-pre.5 | |
Lynx Lynx | =2.8.2-rel.1 | |
Lynx Lynx | =2.8.2-dev.11 | |
Lynx Lynx | =2.8.5-dev.13 | |
Lynx Lynx | =2.8.2-dev.5 | |
Lynx Lynx | =2.8.2-dev.26 | |
Lynx Lynx | =2.8.1-dev.8 | |
Lynx Lynx | =2.8.1-pre.4 | |
Lynx Lynx | =2.8.5-dev.14 | |
Lynx Lynx | =2.8.1-pre.10 | |
Lynx Lynx | =2.8.1-dev.17 | |
Lynx Lynx | =2.8.3-dev.6 | |
Lynx Lynx | =2.8.2-dev.12 | |
Lynx Lynx | =2.8.2-dev.8 | |
Lynx Lynx | =2.8.4-dev3 | |
Lynx Lynx | =2.8.4-dev21 | |
Lynx Lynx | =2.8.2-dev.6 | |
Lynx Lynx | =2.8.1-rel.1 | |
Lynx Lynx | =2.8.6-dev12 | |
Lynx Lynx | =2.8.6-dev2 | |
Lynx Lynx | =2.8.4-pre.2 | |
Lynx Lynx | =2.8.1-dev.27 | |
Lynx Lynx | =2.8.1-dev.16 | |
Lynx Lynx | =2.8.2-pre.1 | |
Lynx Lynx | =2.8.1-dev.14 | |
Lynx Lynx | =2.8.3-dev.4 | |
Lynx Lynx | =2.8.5-dev.2 | |
Lynx Lynx | =2.8.3-dev.1 | |
Lynx Lynx | =2.8.2-dev.9 | |
Lynx Lynx | =2.8.4-dev8 | |
Lynx Lynx | =2.8.2-pre.9 | |
Lynx Lynx | =2.8.2-dev.13 | |
Lynx Lynx | =2.8.3-dev.23 | |
Lynx Lynx | =2.8.3-dev.18 | |
Lynx Lynx | =2.8.2-dev.14 | |
Lynx Lynx | =2.8.2-dev.19 | |
Lynx Lynx | =2.8.3-dev.12 | |
Lynx Lynx | =2.8.2-pre.11 | |
Lynx Lynx | =2.8.1-pre.1 | |
Lynx Lynx | =2.8.3-dev.21 | |
Lynx Lynx | =2.8.1-dev.2 | |
Lynx Lynx | =2.8.3-pre8 | |
Lynx Lynx | =2.8.1-dev.28 | |
Lynx Lynx | =2.8.4-rel.1 | |
Lynx Lynx | =2.8.1-pre.8 | |
Lynx Lynx | =2.8.4-dev13 | |
Lynx Lynx | =2.8.4-dev6 | |
Lynx Lynx | =2.8.2-dev.3 | |
Lynx Lynx | =2.8.3-pre2 | |
Lynx Lynx | =2.8.2-pre.6 | |
Lynx Lynx | =2.8.3-dev.2 | |
Lynx Lynx | =2.8.2-dev.16 | |
Lynx Lynx | =2.8.5-dev.5 | |
Lynx Lynx | =2.8.6-dev7 | |
Lynx Lynx | =2.8.1-pre.6 | |
Lynx Lynx | =2.8.3-dev.16 | |
Lynx Lynx | =2.8.3-dev.19 | |
Lynx Lynx | =2.8.5-dev.1 | |
Lynx Lynx | =2.8.4-dev14 | |
Lynx Lynx | =2.8.5-dev.17 | |
Lynx Lynx | =2.8.1-dev.4 | |
Lynx Lynx | =2.8.1-dev.29 | |
Lynx Lynx | =2.8.4-dev19 | |
Lynx Lynx | =2.8.2-dev.20 | |
Lynx Lynx | =2.8.1-pre.2 | |
Lynx Lynx | =2.8.1-dev.1 | |
Lynx Lynx | =2.8.4-dev9 | |
Lynx Lynx | =2.8.1-dev.22 | |
Lynx Lynx | =2.8.3-pre5 | |
Lynx Lynx | =2.8.5-pre.5 | |
Lynx Lynx | =2.8.6-dev1 | |
Lynx Lynx | =2.8.5-dev.12 | |
Lynx Lynx | =2.8.1-dev.19 | |
Lynx Lynx | =2.8.3-dev.9 | |
Lynx Lynx | =2.8.2-pre.10 | |
Lynx Lynx | =2.8.2-dev.21 | |
Lynx Lynx | =2.8.2-dev.23 | |
Lynx Lynx | =2.8.2-pre.3 | |
Lynx Lynx | =2.8.2-dev.2 | |
Lynx Lynx | =2.8.2-dev.18 | |
Lynx Lynx | =2.8.3-dev.3 | |
Lynx Lynx | =2.8.4-dev20 | |
Lynx Lynx | =2.8.3-dev.15 | |
Lynx Lynx | =2.8.4-dev2 | |
Lynx Lynx | =2.8.6-dev11 | |
Lynx Lynx | =2.8.1-dev.18 | |
Lynx Lynx | =2.8.2-dev.24 | |
Lynx Lynx | =2.8.2-pre.4 | |
Lynx Lynx | =2.8.4-dev16 | |
Lynx Lynx | =2.8.5-pre.3 | |
Lynx Lynx | =2.8.5-dev.11 | |
Lynx Lynx | =2.8.5-dev.8 | |
Lynx Lynx | =2.8.3-dev.22 | |
Lynx Lynx | =2.8.1-dev.21 | |
Lynx Lynx | =2.8.5-dev.15 | |
Lynx Lynx | <=2.8.6 | |
Lynx Lynx | =2.8.1-dev.3 | |
Lynx Lynx | =2.8.4-pre.5 | |
Lynx Lynx | =2.8.2-pre.7 | |
Lynx Lynx | =2.8.1-dev.26 | |
Lynx Lynx | =2.8.1-pre.3 | |
Lynx Lynx | =2.8.5-dev.16 | |
Lynx Lynx | =2.8.4-dev12 | |
Lynx Lynx | =2.8.2-pre.2 | |
Lynx Lynx | =2.8.2-pre.8 | |
Lynx Lynx | =2.8.6-dev10 | |
Lynx Lynx | =2.8.6-dev3 | |
Lynx Lynx | =2.8.2-dev.25 | |
Lynx Lynx | =2.8.4-dev18 | |
Lynx Lynx | =2.8.1-dev.9 | |
Lynx Lynx | =2.8.2-dev.15 | |
Lynx Lynx | =2.8.5-dev.4 | |
Lynx Lynx | =2.8.5-pre.4 | |
Lynx Lynx | =2.8.4-dev7 | |
Lynx Lynx | =2.8.1-dev.12 | |
Lynx Lynx | =2.8.1-dev.11 | |
Lynx Lynx | =2.8.2-dev.4 | |
Lynx Lynx | =2.8.3-pre4 | |
Lynx Lynx | =2.8.6-dev6 | |
Lynx Lynx | =2.8.1-pre.11 | |
Lynx Lynx | =2.8.6-dev13 | |
Lynx Lynx | =2.8.2-dev.7 | |
Lynx Lynx | =2.8.1-dev.23 | |
Lynx Lynx | =2.8.1-dev.24 | |
Lynx Lynx | =2.8.1-dev.6 | |
Lynx Lynx | =2.8.1-pre.9 | |
Lynx Lynx | =2.8.5-rel.1 | |
Lynx Lynx | =2.8.4-dev15 | |
Lynx Lynx | =2.8.3-pre3 | |
Lynx Lynx | =2.8.3-dev.5 | |
Lynx Lynx | =2.8.4-dev1 | |
Lynx Lynx | =2.8.4-dev4 | |
Lynx Lynx | =2.8.6-dev9 | |
Lynx Lynx | =2.8.3-dev.14 | |
Lynx Lynx | =2.8.4-pre.3 | |
Lynx Lynx | =2.8.2-dev.10 | |
Lynx Lynx | =2.8.2-dev.1 | |
Lynx Lynx | =2.8.3-dev.20 | |
Lynx Lynx | =2.8.5-dev.7 | |
Lynx Lynx | =2.8.5-pre.2 | |
Lynx Lynx | =2.8.3-dev.13 | |
Lynx Lynx | =2.8.3-dev.8 | |
Lynx Lynx | =2.8.5-dev.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4690 has a high severity as it allows remote attackers to execute arbitrary commands.
To fix CVE-2008-4690, update Lynx to a version later than 2.8.6-dev.15.
CVE-2008-4690 arises from improper handling of crafted lynxcgi: URLs in Lynx when advanced mode is enabled.
Lynx versions 2.8.6-dev.15 and earlier are affected by CVE-2008-4690.
Exploitation of CVE-2008-4690 may allow an attacker to run arbitrary commands on the server where Lynx is deployed.