CVE Vulnerabilities

CVE-1999-1549

Origin Validation Error

Published: Nov 16, 1999 | Modified: Feb 08, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a secure hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the users configuration file and execute commands.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Lynx Lynx_project 2.7 (including) 2.7 (including)
Lynx Lynx_project 2.8 (including) 2.8 (including)

References