Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.62815
Category:Fedora Local Security Checks
Title:Fedora Core 8 FEDORA-2008-9597 (lynx)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to lynx
announced via advisory FEDORA-2008-9597.

Lynx is a text-based Web browser. Lynx does not display any images,
but it does support frames, tables, and most other HTML tags. One
advantage Lynx has over graphical browsers is speed
Lynx starts and
exits quickly and swiftly displays webpages.

ChangeLog:

* Mon Nov 10 2008 Jiri Moskovcak - 2.8.6-12
- Fixed CVE-2008-4690 lynx: remote arbitrary command execution.
via a crafted lynxcgi: URL (thoger)
* Fri May 30 2008 Jiri Moskovcak - 2.8.6-11
- updated to latest upstream version 2.8.6rel5
- Resolves: #214205
* Wed Jan 9 2008 Jiri Moskovcak - 2.8.6-10
- added telnet, rsh, zip and unzip to BuildRequires
- Resolves: #430508
* Wed Jan 9 2008 Jiri Moskovcak - 2.8.6-9
- fixed crash when using formatting character '$' in translation
- Resolves: #426449
* Tue Dec 11 2007 Ivana Varekova - 2.8.6-8
- add default-colors option, change default setting (#409211)
References:

[ 1 ] Bug #468184 - CVE-2008-4690 lynx: remote arbitrary command execution via a crafted lynxcgi: URL
https://bugzilla.redhat.com/show_bug.cgi?id=468184





Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update lynx' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2008-9597

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-4690
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00066.html
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00143.html
http://www.mandriva.com/security/advisories?name=MDVSA-2008:217
http://www.mandriva.com/security/advisories?name=MDVSA-2008:218
http://www.openwall.com/lists/oss-security/2008/10/09/2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11204
http://www.redhat.com/support/errata/RHSA-2008-0965.html
http://www.securitytracker.com/id?1021105
http://secunia.com/advisories/32416
http://secunia.com/advisories/32967
http://secunia.com/advisories/33568
SuSE Security Announcement: SUSE-SR:2009:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html
XForce ISS Database: lynx-lynxcgi-code-execution(46228)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46228
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.