USN-4800-1: Lynx vulnerabilities
15 March 2021
Several security issues were fixed in Lynx.
Releases
Packages
- lynx - classic non-graphical (text-mode) web browser
Details
It was discovered that Lynx incorrectly handled certain URLs. A remote attacker
could possibly use this issue to obtain sensitive information or other
unspecified impact. This issue only affected Ubuntu 16.04 ESM.
(CVE-2016-9179)
It was discovered that Lynx incorrectly handled certain HTML files. A remote
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2017-1000211)
Thorsten Glaser discovered that Lynx mishandles the userinfo subcomponents of
a URI. An attacker monitoring the network could discover cleartext
credentials because they may appear in SNI data. (CVE-2021-38165)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
lynx
-
2.9.0dev.5-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04
-
lynx
-
2.8.9dev16-3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
lynx
-
2.8.9dev8-4ubuntu1+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.