First published: Fri Nov 17 2017(Updated: )
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lynx Project Lynx | =2.8.9-dev15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000211 is a vulnerability in Lynx before version 2.8.9dev.16 that allows a use after free in the HTML parser resulting in memory disclosure.
CVE-2017-1000211 has a severity rating of medium with a CVSS score of 5.3.
Lynx before version 2.8.9dev.16 is affected by CVE-2017-1000211.
To fix CVE-2017-1000211, upgrade Lynx to version 2.8.9dev.16 or later.
You can find more information about CVE-2017-1000211 at the following references: [http://lynx.invisible-island.net/current/CHANGES.html](http://lynx.invisible-island.net/current/CHANGES.html), [http://www.securityfocus.com/bid/102180](http://www.securityfocus.com/bid/102180), [https://github.com/ThomasDickey/lynx-snapshots/commit/280a61b300a1614f6037efc0902ff7ecf17146e9](https://github.com/ThomasDickey/lynx-snapshots/commit/280a61b300a1614f6037efc0902ff7ecf17146e9).