Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.8.9dev8-4ubuntu1+esm2", "binary_name": "lynx" }, { "binary_version": "2.8.9dev8-4ubuntu1+esm2", "binary_name": "lynx-common" }, { "binary_version": "2.8.9dev8-4ubuntu1+esm2", "binary_name": "lynx-cur" }, { "binary_version": "2.8.9dev8-4ubuntu1+esm2", "binary_name": "lynx-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.8.9dev16-3ubuntu0.1~esm1", "binary_name": "lynx" }, { "binary_version": "2.8.9dev16-3ubuntu0.1~esm1", "binary_name": "lynx-common" }, { "binary_version": "2.8.9dev16-3ubuntu0.1~esm1", "binary_name": "lynx-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.9.0dev.5-1ubuntu0.1~esm1", "binary_name": "lynx" }, { "binary_version": "2.9.0dev.5-1ubuntu0.1~esm1", "binary_name": "lynx-common" }, { "binary_version": "2.9.0dev.5-1ubuntu0.1~esm1", "binary_name": "lynx-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.9.0dev.6-3", "binary_name": "lynx" }, { "binary_version": "2.9.0dev.6-3", "binary_name": "lynx-common" }, { "binary_version": "2.9.0dev.6-3", "binary_name": "lynx-dbgsym" } ] }