CVE-2008-4690OS Command Injection in Lynx

Severity
10.0CRITICALNVD
EPSS
17.5%
top 4.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 22
Latest updateMay 17

Description

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDlynx/lynx2.8.6+6
debiandebian/lynx

🔴Vulnerability Details

1
GHSA
GHSA-wjrg-f7gg-3p35: lynx 22022-05-17

📋Vendor Advisories

2
Red Hat
lynx: remote arbitrary command execution via a crafted lynxcgi: URL2008-10-09
Debian
CVE-2008-4690: lynx - lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configur...2008

💬Community

1
Bugzilla
CVE-2008-4690 lynx: remote arbitrary command execution via a crafted lynxcgi: URL2008-10-23