Thursday, October 27, 2005

Critical Lynx Security Threat

Upgrade lynx today
"An attacker could ... execute arbitrary code as the user running lynx" - Red Hat

An updated lynx package that corrects a security flaw is now available.

This update has been rated as having critical security impact by the Red Hat Security Response Team.

Lynx is a text-based Web browser.

Ulf Harnhammar discovered a stack overflow bug in Lynx when handling connections to NNTP (news) servers. An attacker could create a web page
redirecting to a malicious news server which could execute arbitrary code
as the user running lynx. The Common Vulnerabilities and Exposures project
assigned the name CAN-2005-3120 to this issue.

Users should update to this erratum package, which contains a backported
patch to correct this issue.

Upgrade your lynx browser today and save your server!


Post a Comment

Links to this post:

Create a Link

<< Home