CVE-2017-1000211

Priority
Description
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML
parser resulting in memory disclosure, because HTML_put_string() can append
a chunk onto itself.
Ubuntu-Description
It was discovered that Lynx incorrectly handled certain HTML files. A remote
attacker could possibly use this issue to obtain sensitive information.
Notes
tyhicks2.8.9dev.16 contained the fix
Package
Source: lynx (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 18.04 LTS (Bionic Beaver):not-affected
Ubuntu 19.10 (Eoan Ermine):not-affected
Ubuntu 20.04 (Focal Fossa):not-affected
More Information

Updated: 2020-04-24 03:35:05 UTC (commit d3f8a6ed481830fb100109a132bef581fc4176fe)