CVE-2014-5002
published 2018-01-10CVE-2014-5002: The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing…
PriorityP434high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.52%
41.4th percentile
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lynx_project | lynx | < 1.0.0 | 1.0.0 |
| lynx_project | lynx | >= 0 < 1.0.0 | 1.0.0 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
lynx doesn't properly sanitize user input and exposes database password to unauthorized users
osv·2018-01-24
CVE-2014-5002 [HIGH] lynx doesn't properly sanitize user input and exposes database password to unauthorized users
lynx doesn't properly sanitize user input and exposes database password to unauthorized users
The lynx gem prior to 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
As of version 1.0.0, lynx no longer supports a `--password` option. Passwords are only configured in a configuration file, so it's no longer possible to expose passwords on the command line.
GHSA
lynx doesn't properly sanitize user input and exposes database password to unauthorized users
ghsa·2018-01-24
CVE-2014-5002 [HIGH] CWE-200 lynx doesn't properly sanitize user input and exposes database password to unauthorized users
lynx doesn't properly sanitize user input and exposes database password to unauthorized users
The lynx gem prior to 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
As of version 1.0.0, lynx no longer supports a `--password` option. Passwords are only configured in a configuration file, so it's no longer possible to expose passwords on the command line.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2014/07/07/23http://www.openwall.com/lists/oss-security/2014/07/17/5http://www.vapid.dhs.org/advisories/lynx-0.2.0.htmlhttps://github.com/panthomakos/lynx/issues/3http://www.openwall.com/lists/oss-security/2014/07/07/23http://www.openwall.com/lists/oss-security/2014/07/17/5http://www.vapid.dhs.org/advisories/lynx-0.2.0.htmlhttps://github.com/panthomakos/lynx/issues/3
2018-01-10
Published