[Secure-testing-team] Bug#843258: ynx: CVE-2016-9179

Salvatore Bonaccorso carnil at debian.org
Sat Nov 5 15:22:10 UTC 2016

Source: lynx
Version: 2.8.9dev9-1
Severity: important
Tags: security upstream


the following vulnerability was published for lynx. TTBOMK there is no
upstream patch yet, but has been promised to look into it.

invalid URL parsing with '?'

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-9179
[1] http://www.openwall.com/lists/oss-security/2016/11/03/4
[2] http://www.openwall.com/lists/oss-security/2016/11/04/8


More information about the Secure-testing-team mailing list