Описание
Security update for lynx
This update for lynx fixes the following issues:
Security issue fixed:
- CVE-2017-1000211: Fix use after free in the HTMLparser that can resulting in memory disclosure (bsc#1068885).
Список пакетов
SUSE Linux Enterprise Software Development Kit 11 SP4
lynx-2.8.6-146.3.1
Ссылки
- Link for SUSE-SU-2017:3180-1
- E-Mail link for SUSE-SU-2017:3180-1
- SUSE Security Ratings
- SUSE Bug 1068885
- SUSE CVE CVE-2017-1000211 page
Описание
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:lynx-2.8.6-146.3.1
Ссылки
- CVE-2017-1000211
- SUSE Bug 1068885