CVE-2005-2929
Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.92%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in some environments.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.92% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- university of kansas/lynx
- Source
- cve@mitre.org
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.7/SCOSA-2006.7.txt
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.55/SCOSA-2005.55.txt
- http://secunia.com/advisories/17372Vendor Advisory
- http://secunia.com/advisories/17512Vendor Advisory
- http://secunia.com/advisories/17546Vendor Advisory
- http://secunia.com/advisories/17556Vendor Advisory
- http://secunia.com/advisories/17576Vendor Advisory
- http://secunia.com/advisories/17666Vendor Advisory
- http://secunia.com/advisories/17757Vendor Advisory
- http://secunia.com/advisories/18051Vendor Advisory
- http://secunia.com/advisories/18376Vendor Advisory
- http://secunia.com/advisories/18659Vendor Advisory
- http://securityreason.com/securityalert/173
- http://securitytracker.com/id?1015195
- http://support.avaya.com/elmodocs2/security/ASA-2006-035.htm
- http://www.gentoo.org/security/en/glsa/glsa-200511-09.xml
- http://www.idefense.com/application/poi/display?id=338&type=vulnerabilitiesPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:211
- http://www.openpkg.org/security/OpenPKG-SA-2005.026-lynx.html
- http://www.redhat.com/support/errata/RHSA-2005-839.html
- http://www.securityfocus.com/archive/1/419763/100/0/threaded
- http://www.securityfocus.com/bid/15395
- http://www.vupen.com/english/advisories/2005/2394Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23119
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9712
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.7/SCOSA-2006.7.txt
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.55/SCOSA-2005.55.txt
- http://secunia.com/advisories/17372Vendor Advisory
- http://secunia.com/advisories/17512Vendor Advisory
- http://secunia.com/advisories/17546Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.