lynx (SSA:2005-310-03)
Posted on: 11/07/2005 01:46 AM
New Lynx packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix a security issue. An overflow could result in the execution of arbitrary code when using Lynx to connect to a malicious NNTP server.
More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database:
Here are the details from the Slackware 10.2 ChangeLog: +--------------------------+ patches/packages/lynx-2.8.5rel.5-i486-1.tgz: Upgraded to lynx-2.8.5rel.5. Fixes an issue where the handling of Asian characters when using lynx to connect to an NNTP server (is this a common use?) could result in a buffer overflow causing the execution of arbitrary code. For more details, see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3120 (* Security fix *) +--------------------------+
Where to find the new packages: +-----------------------------+