CVE-2021-38165: Medium severity Lynx Project Lynx vulnerability
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/lynxto a version that resolves this vulnerability.Fixed in 2.8.9rel.1-3+deb10u1Fixed in 2.9.0dev.6-3~deb11u1Fixed in 2.9.0dev.12-1 - Upgrade
Upgrade
debian/lynxto a version that resolves this vulnerability.Fixed in 2.9.0dev.9-1Fixed in 2.9.0dev.6-3Fixed in 2.9.0dev.6-3~deb11u1Fixed in 2.8.9rel.1-3+deb10u1
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-38165.
What is the severity of CVE-2021-38165?
The severity of CVE-2021-38165 is medium with a CVSS score of 5.3.
What is the affected software?
The affected software is Lynx versions 2.8.9 and prior.
How can remote attackers exploit CVE-2021-38165?
Remote attackers can exploit CVE-2021-38165 by discovering cleartext credentials through the mishandling of the userinfo subcomponent of a URI.
Are there any known references for CVE-2021-38165?
Yes, there are references available for CVE-2021-38165. You can find them at the following links: [link1](http://www.openwall.com/lists/oss-security/2021/08/07/11), [link2](http://www.openwall.com/lists/oss-security/2021/08/07/12), [link3](http://www.openwall.com/lists/oss-security/2021/08/07/9).