CVE-2008-4690: Critical severity lynx vulnerability
lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4690?
CVE-2008-4690 has a high severity as it allows remote attackers to execute arbitrary commands.
How do I fix CVE-2008-4690?
To fix CVE-2008-4690, update Lynx to a version later than 2.8.6-dev.15.
What causes the vulnerability in CVE-2008-4690?
CVE-2008-4690 arises from improper handling of crafted lynxcgi: URLs in Lynx when advanced mode is enabled.
Which versions of Lynx are affected by CVE-2008-4690?
Lynx versions 2.8.6-dev.15 and earlier are affected by CVE-2008-4690.
What are the potential impacts of exploiting CVE-2008-4690?
Exploitation of CVE-2008-4690 may allow an attacker to run arbitrary commands on the server where Lynx is deployed.