A CVE has been assigned for a security issue in lynx: http://openwall.com/lists/oss-security/2016/11/04/1 No fix is available yet, but the upstream author said that he would work on it. Mageia 5 is also affected.
Whiteboard: (none) => MGA5TOO
Already assigning to all packagers collectively. (There is no registered maintainer for this package.)
CC: (none) => marja11Assignee: bugsquad => pkg-bugs
how to test this ?
CC: (none) => mageia
ok fixed in : http://lynx.invisible-island.net/current/CHANGES.html#index-v2.8.9dev.10
but i don't find where the code is hosted
Fedora has issued an advisory for this today (February 14): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FUXKJDF62YGEI7SVFFUYQ56QCKESXF3W/ Hopefully we can find a patch for this so we don't have to get back on the development release train.
URL: (none) => https://lwn.net/Vulnerabilities/714582/
Suggested advisory: ======================== The updated package fix a security vulnerability: Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host. (CVE-2016-9179) References: http://openwall.com/lists/oss-security/2016/11/04/1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9179 ======================== Updated packages in core/updates_testing: ======================== lynx-2.8.8-1.rel2.3.1.mga5 from SRPMS: lynx-2.8.8-1.rel2.3.1.mga5.src.rpm
Status: NEW => ASSIGNEDCC: (none) => nicolas.salgueroVersion: Cauldron => 5Assignee: pkg-bugs => qa-bugsWhiteboard: MGA5TOO => (none)
32-bit version Installed lynx and was able to browse around the Mageia website. Seems to work from a base perspective
CC: (none) => brtians1Whiteboard: (none) => mga5-32-ok
CC: (none) => davidwhodginsWhiteboard: mga5-32-ok => mga5-32-ok advisory
Trying http://www.google.ca?localhost both before and after the update fails, so not sure how to recreate the bug. Normal web browsing is working, so validating the update.
Keywords: (none) => validated_updateWhiteboard: mga5-32-ok advisory => mga5-32-ok advisory MGA5-64-OKCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0052.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED