CVE-2016-9179 PUBLISHED

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

EPSS 0.27% · 50.8th percentile

Risk Scores

EPSS Score
0.27%
50.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlynx0, 2.8.9dev8-4ubuntu1

Timeline

References

Open in Interactive Console →