Advisory Published
Updated

CVE-2008-4690

First published: Wed Oct 22 2008(Updated: )

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Lynx Lynx=2.8.3-pre1
Lynx Lynx=2.8.1-dev.5
Lynx Lynx=2.8.5-dev.6
Lynx Lynx=2.8.1-dev.20
Lynx Lynx=2.8.2-dev.17
Lynx Lynx=2.8.6-dev5
Lynx Lynx=2.8.4-dev17
Lynx Lynx=2.8.6-dev4
Lynx Lynx=2.8.4-dev11
Lynx Lynx=2.8.4-dev10
Lynx Lynx=2.8.5-dev.3
Lynx Lynx=2.8.1-dev.7
Lynx Lynx=2.8.3-pre6
Lynx Lynx=2.8.6-dev8
Lynx Lynx=2.8.5-pre.1
Lynx Lynx=2.8.2-dev.22
Lynx Lynx=2.8.3-dev.11
Lynx Lynx=2.8.4-pre.1
Lynx Lynx=2.8.5-dev.9
Lynx Lynx=2.8.1-rel.2
Lynx Lynx=2.8.1-dev.10
Lynx Lynx=2.8.3-dev.7
Lynx Lynx=2.8.3-dev.17
Lynx Lynx=2.8.1-dev.13
Lynx Lynx=2.8.1-pre.5
Lynx Lynx=2.8.4-dev5
Lynx Lynx=2.8.4-pre.4
Lynx Lynx=2.8.6-dev14
Lynx Lynx=2.8.1-dev.15
Lynx Lynx=2.8.3-rel1
Lynx Lynx=2.8.3-pre7
Lynx Lynx=2.8.1-pre.7
Lynx Lynx=2.8.3-dev.10
Lynx Lynx=2.8.2-pre.5
Lynx Lynx=2.8.2-rel.1
Lynx Lynx=2.8.2-dev.11
Lynx Lynx=2.8.5-dev.13
Lynx Lynx=2.8.2-dev.5
Lynx Lynx=2.8.2-dev.26
Lynx Lynx=2.8.1-dev.8
Lynx Lynx=2.8.1-pre.4
Lynx Lynx=2.8.5-dev.14
Lynx Lynx=2.8.1-pre.10
Lynx Lynx=2.8.1-dev.17
Lynx Lynx=2.8.3-dev.6
Lynx Lynx=2.8.2-dev.12
Lynx Lynx=2.8.2-dev.8
Lynx Lynx=2.8.4-dev3
Lynx Lynx=2.8.4-dev21
Lynx Lynx=2.8.2-dev.6
Lynx Lynx=2.8.1-rel.1
Lynx Lynx=2.8.6-dev12
Lynx Lynx=2.8.6-dev2
Lynx Lynx=2.8.4-pre.2
Lynx Lynx=2.8.1-dev.27
Lynx Lynx=2.8.1-dev.16
Lynx Lynx=2.8.2-pre.1
Lynx Lynx=2.8.1-dev.14
Lynx Lynx=2.8.3-dev.4
Lynx Lynx=2.8.5-dev.2
Lynx Lynx=2.8.3-dev.1
Lynx Lynx=2.8.2-dev.9
Lynx Lynx=2.8.4-dev8
Lynx Lynx=2.8.2-pre.9
Lynx Lynx=2.8.2-dev.13
Lynx Lynx=2.8.3-dev.23
Lynx Lynx=2.8.3-dev.18
Lynx Lynx=2.8.2-dev.14
Lynx Lynx=2.8.2-dev.19
Lynx Lynx=2.8.3-dev.12
Lynx Lynx=2.8.2-pre.11
Lynx Lynx=2.8.1-pre.1
Lynx Lynx=2.8.3-dev.21
Lynx Lynx=2.8.1-dev.2
Lynx Lynx=2.8.3-pre8
Lynx Lynx=2.8.1-dev.28
Lynx Lynx=2.8.4-rel.1
Lynx Lynx=2.8.1-pre.8
Lynx Lynx=2.8.4-dev13
Lynx Lynx=2.8.4-dev6
Lynx Lynx=2.8.2-dev.3
Lynx Lynx=2.8.3-pre2
Lynx Lynx=2.8.2-pre.6
Lynx Lynx=2.8.3-dev.2
Lynx Lynx=2.8.2-dev.16
Lynx Lynx=2.8.5-dev.5
Lynx Lynx=2.8.6-dev7
Lynx Lynx=2.8.1-pre.6
Lynx Lynx=2.8.3-dev.16
Lynx Lynx=2.8.3-dev.19
Lynx Lynx=2.8.5-dev.1
Lynx Lynx=2.8.4-dev14
Lynx Lynx=2.8.5-dev.17
Lynx Lynx=2.8.1-dev.4
Lynx Lynx=2.8.1-dev.29
Lynx Lynx=2.8.4-dev19
Lynx Lynx=2.8.2-dev.20
Lynx Lynx=2.8.1-pre.2
Lynx Lynx=2.8.1-dev.1
Lynx Lynx=2.8.4-dev9
Lynx Lynx=2.8.1-dev.22
Lynx Lynx=2.8.3-pre5
Lynx Lynx=2.8.5-pre.5
Lynx Lynx=2.8.6-dev1
Lynx Lynx=2.8.5-dev.12
Lynx Lynx=2.8.1-dev.19
Lynx Lynx=2.8.3-dev.9
Lynx Lynx=2.8.2-pre.10
Lynx Lynx=2.8.2-dev.21
Lynx Lynx=2.8.2-dev.23
Lynx Lynx=2.8.2-pre.3
Lynx Lynx=2.8.2-dev.2
Lynx Lynx=2.8.2-dev.18
Lynx Lynx=2.8.3-dev.3
Lynx Lynx=2.8.4-dev20
Lynx Lynx=2.8.3-dev.15
Lynx Lynx=2.8.4-dev2
Lynx Lynx=2.8.6-dev11
Lynx Lynx=2.8.1-dev.18
Lynx Lynx=2.8.2-dev.24
Lynx Lynx=2.8.2-pre.4
Lynx Lynx=2.8.4-dev16
Lynx Lynx=2.8.5-pre.3
Lynx Lynx=2.8.5-dev.11
Lynx Lynx=2.8.5-dev.8
Lynx Lynx=2.8.3-dev.22
Lynx Lynx=2.8.1-dev.21
Lynx Lynx=2.8.5-dev.15
Lynx Lynx<=2.8.6
Lynx Lynx=2.8.1-dev.3
Lynx Lynx=2.8.4-pre.5
Lynx Lynx=2.8.2-pre.7
Lynx Lynx=2.8.1-dev.26
Lynx Lynx=2.8.1-pre.3
Lynx Lynx=2.8.5-dev.16
Lynx Lynx=2.8.4-dev12
Lynx Lynx=2.8.2-pre.2
Lynx Lynx=2.8.2-pre.8
Lynx Lynx=2.8.6-dev10
Lynx Lynx=2.8.6-dev3
Lynx Lynx=2.8.2-dev.25
Lynx Lynx=2.8.4-dev18
Lynx Lynx=2.8.1-dev.9
Lynx Lynx=2.8.2-dev.15
Lynx Lynx=2.8.5-dev.4
Lynx Lynx=2.8.5-pre.4
Lynx Lynx=2.8.4-dev7
Lynx Lynx=2.8.1-dev.12
Lynx Lynx=2.8.1-dev.11
Lynx Lynx=2.8.2-dev.4
Lynx Lynx=2.8.3-pre4
Lynx Lynx=2.8.6-dev6
Lynx Lynx=2.8.1-pre.11
Lynx Lynx=2.8.6-dev13
Lynx Lynx=2.8.2-dev.7
Lynx Lynx=2.8.1-dev.23
Lynx Lynx=2.8.1-dev.24
Lynx Lynx=2.8.1-dev.6
Lynx Lynx=2.8.1-pre.9
Lynx Lynx=2.8.5-rel.1
Lynx Lynx=2.8.4-dev15
Lynx Lynx=2.8.3-pre3
Lynx Lynx=2.8.3-dev.5
Lynx Lynx=2.8.4-dev1
Lynx Lynx=2.8.4-dev4
Lynx Lynx=2.8.6-dev9
Lynx Lynx=2.8.3-dev.14
Lynx Lynx=2.8.4-pre.3
Lynx Lynx=2.8.2-dev.10
Lynx Lynx=2.8.2-dev.1
Lynx Lynx=2.8.3-dev.20
Lynx Lynx=2.8.5-dev.7
Lynx Lynx=2.8.5-pre.2
Lynx Lynx=2.8.3-dev.13
Lynx Lynx=2.8.3-dev.8
Lynx Lynx=2.8.5-dev.10

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2008-4690?

    CVE-2008-4690 has a high severity as it allows remote attackers to execute arbitrary commands.

  • How do I fix CVE-2008-4690?

    To fix CVE-2008-4690, update Lynx to a version later than 2.8.6-dev.15.

  • What causes the vulnerability in CVE-2008-4690?

    CVE-2008-4690 arises from improper handling of crafted lynxcgi: URLs in Lynx when advanced mode is enabled.

  • Which versions of Lynx are affected by CVE-2008-4690?

    Lynx versions 2.8.6-dev.15 and earlier are affected by CVE-2008-4690.

  • What are the potential impacts of exploiting CVE-2008-4690?

    Exploitation of CVE-2008-4690 may allow an attacker to run arbitrary commands on the server where Lynx is deployed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203