Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-7234Lynx vulnerability

6 documents6 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 66.26%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedOct 27
Latest updateMay 1

Description

Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

NVDlynx/lynx2.8.6+6
debiandebian/lynx

🔴Vulnerability Details

1
GHSA
GHSA-cg3w-xm4w-x9rw: Untrusted search path vulnerability in Lynx before 22022-05-01

💥Exploits & PoCs

1
Exploit-DB
Lynx 2.8 - '.mailcap'/'.mime.type' Local Code Execution2008-11-03

📋Vendor Advisories

2
Red Hat
lynx: .mailcap and .mime.types files read from CWD2006-10-03
Debian
CVE-2006-7234: lynx - Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users...2006

💬Community

1
Bugzilla
CVE-2006-7234 lynx: .mailcap and .mime.types files read from CWD2006-11-06