UBUNTU-CVE-2021-38165
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-38165
UBUNTU-CVE-2021-38165
Summary:
Details: Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
References: https://ubuntu.com/security/CVE-2021-38165, https://lists.nongnu.org/archive/html/lynx-dev/2021-08/msg00002.html, https://lynx.invisible-island.net/current/CHANGES.html#v2.9.0dev.9, https://invisible-mirror.net/archives/lynx/patches/lynx2.9.0dev.9.patch.gz, https://www.openwall.com/lists/oss-security/2021/08/07/1, https://github.com/w3c/libwww/blob/f010b4cc58d32f34b162f0084fe093f7097a61f0/Library/src/HTParse.c#L118, https://lynx.invisible-island.net/current/CHANGES.html, https://bugs.debian.org/991971, https://www.openwall.com/lists/oss-security/2021/08/07/11, http://www.openwall.com/lists/oss-security/2021/08/07/9, https://ubuntu.com/security/notices/USN-4800-1, https://www.cve.org/CVERecord?id=CVE-2021-38165
Affected packages
Package
Name: lynx
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
