RHSA-2008:0965: Important: lynx security update
Lynx is a text-based Web browser.An arbitrary command execution flaw was found in the Lynx "lynxcgi:" URIhandler. An attacker could create a web page redirecting to a malicious URLthat could execute arbitrary code as the user running Lynx in thenon-default "Advanced" user mode. (CVE-2008-4690)Note: In these updated lynx packages, Lynx will always prompt users beforeloading a "lynxcgi:" URI. Additionally, the default lynx.cfg configurationfile now marks all "lynxcgi:" URIs as untrusted by default.A flaw was found in a way Lynx handled ".mailcap" and ".mime.types"configuration files. Files in the browser's current working directory wereopened before those in the user's home directory. A local attacker, able toconvince a user to run Lynx in a directory under their control, couldpossibly execute arbitrary commands as the user running Lynx. (CVE-2006-7234)All users of Lynx are advised to upgrade to this updated package, whichcontains backported patches correcting these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0965?
The severity of RHSA-2008:0965 is classified as important due to the potential for arbitrary command execution.
How do I fix RHSA-2008:0965?
To fix RHSA-2008:0965, update Lynx to versions 2.8.5-28.1.el5_2.1 or 2.8.5-18.2.el4_7.1 or later.
What is the impact of the vulnerability in RHSA-2008:0965?
The impact of the RHSA-2008:0965 vulnerability allows an attacker to execute arbitrary commands through malicious URLs.
Which software versions are affected by RHSA-2008:0965?
RHSA-2008:0965 affects Lynx versions prior to 2.8.5-28.1.el5_2.1 and 2.8.5-18.2.el4_7.1.
Can the vulnerability in RHSA-2008:0965 be exploited remotely?
Yes, the vulnerability in RHSA-2008:0965 can be exploited remotely through specially crafted web pages.