Mandriva: Subject: [Security Announce] [ MDVSA-2008:218 ] lynx


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) Mandriva: Subject: [Security Announce] [ MDVSA-2008:218 ] lynx
# 1  
Old 10-28-2008
Mandriva: Subject: [Security Announce] [ MDVSA-2008:218 ] lynx

LinuxSecurity.com: A vulnerability was found in the Lynxcgi: URI handler that could allow an attacker to create a web page redirecting to a malicious URL that would execute arbitrary code as the user running Lynx, if they were using the non-default Advanced user mode (CVE-2008-4690). This update corrects these issues and, in addition, makes Lynx always prompt the user before loading a lynxcgi: URI. As well, the default lynx.cfg configuration file marks all lynxcgi: URIs as untrusted.

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question