Lynx does not verify that the servers certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS function.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lynx | Lynx | - (including) | - (including) |
Lynx | Ubuntu | hardy | * |
Lynx | Ubuntu | upstream | * |
Lynx-cur | Ubuntu | hardy | * |
Lynx-cur | Ubuntu | lucid | * |
Lynx-cur | Ubuntu | oneiric | * |
Lynx-cur | Ubuntu | precise | * |
Lynx-cur | Ubuntu | quantal | * |
Lynx-cur | Ubuntu | upstream | * |