The remote host is missing updates announced in advisory CLA-2003:720.
Lynx is a text terminal based web browser.
Ulf Harnhammar reported[1] a CRLF (Carriage Return, Line Feed) injection vulnerability in lynx. When handling a URL supplied through the command line, lynx does not filter out characters such as spaces, CR, LF, etc, which allows an attacker to inject HTTP headers and cause program misbehavior[2] by using a specially crafted URL.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2002-1405 to this issue[3].
The package distributed with Conectiva Linux 9 (lynx-2.8.4-25963cl) already contains a fix and is not vulnerable to this problem.
Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade'