Vulnerability Bulletins |
Denegación de servicio en lynx |
|
Vulnerability classification |
|
Property | Value |
Confidence level | Oficial |
Impact | Denegación de Servicio |
Dificulty | Principiante |
Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
Property | Value |
Affected manufacturer | GNU/Linux |
Affected software | lynx |
Description |
|
Se ha descubierto una vulnerabilidad en el navegador Web lynx. La vulnerabilidad reside en el parseo de código HTML especialmente diseñado, proceso durante el cuál lynx podría entrar en un bucle infinito. La explotación de esta vulnerabilidad podría permitir a un atacante remoto provocar una situación de denegación de servicio del navegador lynx, mediante una página Web especialmente diseñada que la víctima debe intentar visualizar. |
|
Solution |
|
Actualización de software Debian Linux (lynx) Debian Linux 3.0 Source http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4.dsc http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4.diff.gz http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b.orig.tar.gz Alpha architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_alpha.deb ARM architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_arm.deb Intel IA-32 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_i386.deb Intel IA-64 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_ia64.deb HP Precision architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_hppa.deb Motorola 680x0 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_m68k.deb Big endian MIPS architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_mips.deb Little endian MIPS architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_mipsel.deb PowerPC architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_powerpc.deb IBM S/390 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_s390.deb Sun Sparc architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.4.1b-3.4_sparc.deb Debian Linux 3.1 Source http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2.dsc http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2.diff.gz http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_alpha.deb AMD64 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_amd64.deb ARM architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_arm.deb Intel IA-32 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_i386.deb Intel IA-64 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_ia64.deb HP Precision architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_hppa.deb Motorola 680x0 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_m68k.deb Big endian MIPS architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_mips.deb Little endian MIPS architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_mipsel.deb PowerPC architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_powerpc.deb IBM S/390 architecture: http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx/lynx_2.8.5-2sarge2_sparc.deb Debian Linux (lynx-ssl) Debian Linux 3.0 Source http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3.dsc http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3.diff.gz http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b.orig.tar.gz Alpha http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_alpha.deb ARM http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx-ssl/lynx-ssl_2.8.4.1b-3.3_sparc.deb Debian (lynx 2.8.5, 2.8.6) Debian Linux 3.0 Source http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1.dsc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1.diff.gz http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5.orig.tar.gz Architecture independent http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur-wrapper_2.8.5-2.5woody1_all.deb Alpha http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_alpha.deb ARM http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.5-2.5woody1_sparc.deb Debian Linux 3.1 Source http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1.dsc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1.diff.gz http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6.orig.tar.gz Architecture independent http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur-wrapper_2.8.6-9sarge1_all.deb Alpha http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_alpha.deb AMD64 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_amd64.deb ARM http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_arm.deb Intel IA-32 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_i386.deb Intel IA-64 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_ia64.deb HP Precision http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_hppa.deb Motorola 680x0 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_m68k.deb Big endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_mips.deb Little endian MIPS http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_mipsel.deb PowerPC http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_powerpc.deb IBM S/390 http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_s390.deb Sun Sparc http://security.debian.org/pool/updates/main/l/lynx-cur/lynx-cur_2.8.6-9sarge1_sparc.deb |
|
Standar resources |
|
Property | Value |
CVE | CVE-2004-1617 |
BID | |
Other resources |
|
Debian Security Advisory DSA 1076-1 http://lists.debian.org/debian-security-announce/debian-security-announce-2006/msg00162.html Debian Security Advisory DSA 1077-1 http://lists.debian.org/debian-security-announce/debian-security-announce-2006/msg00163.html Debian Security Advisory (DSA 1085-1) http://lists.debian.org/debian-security-announce/debian-security-announce-2006/msg00171.html |
Version history |
||
Version | Comments | Date |
1.0 | Aviso emitido | 2006-05-29 |
1.1 | Aviso emitido por Debian (DSA 1085-1) | 2006-06-02 |