CVE-2010-2810: Buffer Overflow
Heap-based buffer overflow in the converttoidna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed URL containing a % (percent) character in the domain name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2810?
CVE-2010-2810 is classified as a medium severity vulnerability due to its potential to cause denial of service or execute arbitrary code.
How do I fix CVE-2010-2810?
To fix CVE-2010-2810, upgrade to a patched version of Lynx that addresses the buffer overflow issue.
Which versions of Lynx are affected by CVE-2010-2810?
CVE-2010-2810 affects Lynx versions 2.8.8-dev.1 through 2.8.8-dev.4.
Can CVE-2010-2810 allow remote code execution?
Yes, CVE-2010-2810 can allow remote attackers to execute arbitrary code through specially crafted URLs.
What type of vulnerability is CVE-2010-2810?
CVE-2010-2810 is a heap-based buffer overflow vulnerability.