CVE-2008-4690

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html
http://secunia.com/advisories/32416 Vendor Advisory
http://secunia.com/advisories/32967
http://secunia.com/advisories/33568
http://www.mandriva.com/security/advisories?name=MDVSA-2008:217
http://www.mandriva.com/security/advisories?name=MDVSA-2008:218
http://www.openwall.com/lists/oss-security/2008/10/09/2
http://www.redhat.com/support/errata/RHSA-2008-0965.html Vendor Advisory
http://www.securitytracker.com/id?1021105
https://exchange.xforce.ibmcloud.com/vulnerabilities/46228
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11204
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00066.html
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00143.html
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html
http://secunia.com/advisories/32416 Vendor Advisory
http://secunia.com/advisories/32967
http://secunia.com/advisories/33568
http://www.mandriva.com/security/advisories?name=MDVSA-2008:217
http://www.mandriva.com/security/advisories?name=MDVSA-2008:218
http://www.openwall.com/lists/oss-security/2008/10/09/2
http://www.redhat.com/support/errata/RHSA-2008-0965.html Vendor Advisory
http://www.securitytracker.com/id?1021105
https://exchange.xforce.ibmcloud.com/vulnerabilities/46228
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11204
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00066.html
https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00143.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lynx:lynx:*:dev15:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.12:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.13:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.14:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.15:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.16:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.17:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.18:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.19:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.20:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.21:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.22:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.23:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.24:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.26:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.27:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.28:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.29:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:dev.9:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:pre.9:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:rel.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.1:rel.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.12:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.13:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.14:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.15:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.16:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.17:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.18:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.19:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.20:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.21:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.22:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.23:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.24:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.25:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.26:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:dev.9:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:pre.9:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.2:rel.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.12:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.13:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.14:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.15:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.16:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.17:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.18:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.19:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.20:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.21:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.22:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.23:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:dev.9:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:pre8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.3:rel1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev12:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev13:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev14:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev15:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev16:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev17:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev18:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev19:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev20:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev21:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:dev9:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:pre.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:pre.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:pre.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:pre.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:pre.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.4:rel.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.12:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.13:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.14:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.15:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.16:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.17:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:dev.9:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:pre.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:pre.2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:pre.3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:pre.4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:pre.5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.5:rel.1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev1:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev10:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev11:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev12:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev13:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev14:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev2:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev3:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev4:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev5:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev6:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev7:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev8:*:*:*:*:*:*
cpe:2.3:a:lynx:lynx:2.8.6:dev9:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.html -
References () http://secunia.com/advisories/32416 - Vendor Advisory () http://secunia.com/advisories/32416 - Vendor Advisory
References () http://secunia.com/advisories/32967 - () http://secunia.com/advisories/32967 -
References () http://secunia.com/advisories/33568 - () http://secunia.com/advisories/33568 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:217 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:217 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:218 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:218 -
References () http://www.openwall.com/lists/oss-security/2008/10/09/2 - () http://www.openwall.com/lists/oss-security/2008/10/09/2 -
References () http://www.redhat.com/support/errata/RHSA-2008-0965.html - Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2008-0965.html - Vendor Advisory
References () http://www.securitytracker.com/id?1021105 - () http://www.securitytracker.com/id?1021105 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/46228 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/46228 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11204 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11204 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00066.html - () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00066.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00143.html - () https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00143.html -

Information

Published : 2008-10-22 18:00

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4690

Mitre link : CVE-2008-4690

CVE.ORG link : CVE-2008-4690


JSON object : View

Products Affected

lynx

  • lynx