Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53858
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-210)
Summary:The remote host is missing an update for the Debian 'lynx, lynx-ssl' package(s) announced via the DSA-210 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'lynx, lynx-ssl' package(s) announced via the DSA-210 advisory.

Vulnerability Insight:
lynx (a text-only web browser) did not properly check for illegal characters in all places, including processing of command line options, which could be used to insert extra HTTP headers in a request.

For Debian GNU/Linux 2.2/potato this has been fixed in version 2.8.3-1.1 of the lynx package and version 2.8.3.1-1.1 of the lynx-ssl package.

For Debian GNU/Linux 3.0/woody this has been fixed in version 2.8.4.1b-3.2 of the lynx package and version 1:2.8.4.1b-3.1 of the lynx-ssl package.

Affected Software/OS:
'lynx, lynx-ssl' package(s) on Debian 3.0.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1405
BugTraq ID: 5499
http://www.securityfocus.com/bid/5499
Bugtraq: 20020819 Lynx CRLF Injection (Google Search)
http://marc.info/?l=bugtraq&m=102978118411977&w=2
Bugtraq: 20020822 Lynx CRLF Injection, part two (Google Search)
http://marc.info/?l=bugtraq&m=103003793418021&w=2
Caldera Security Advisory: CSSA-2002-049.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-049.0.txt
Debian Security Information: DSA-210 (Google Search)
http://www.debian.org/security/2002/dsa-210
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:023
http://www.redhat.com/support/errata/RHSA-2003-029.html
http://www.redhat.com/support/errata/RHSA-2003-030.html
http://www.trustix.net/errata/misc/2002/TSL-2002-0085-lynx-ssl.asc.txt
http://www.iss.net/security_center/static/9887.php
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.