Vulnerability Description
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lynx Project | Lynx | 2.7 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=94286509804526&w=2ExploitMailing List
- http://www.securityfocus.com/bid/804Broken LinkExploitThird Party Advisory
- http://marc.info/?l=bugtraq&m=94286509804526&w=2ExploitMailing List
- http://www.securityfocus.com/bid/804Broken LinkExploitThird Party Advisory
FAQ
What is CVE-1999-1549?
CVE-1999-1549 is a vulnerability with a CVSS score of 7.8 (HIGH). Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that...
How severe is CVE-1999-1549?
CVE-1999-1549 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1549?
Check the references section above for vendor advisories and patch information. Affected products include: Lynx Project Lynx.