5.3
CVSSv3

CVE-2021-38165

Published: 07/08/2021 Updated: 07/11/2023
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

Lynx up to and including 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote malicious users to discover cleartext credentials because they may appear in SNI data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lynx project lynx

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Thorsten Glaser and Axel Beckert reported that lynx, a non-graphical (text-mode) web browser, does not properly handle the userinfo subcomponent of a URI, which can lead to leaking of credential in cleartext in SNI data For the stable distribution (buster), this problem has been fixed in version 289rel1-3+deb10u1 We recommend that you upgrade ...
Lynx through 289 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data (CVE-2021-38165) ...
Lynx through 289 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data ...
HTParse in Lynx through 289 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data or HTTP headers ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Bug#991971: [Lynx-dev] bug in Lynx' SSL certificate validation -&gt; leaks password in clear text via SNI (under some circu ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: Re: Bug#991971: [Lynx-dev] bug in Lynx' SSL certificate validation -&gt; leaks password in clear text via SNI (under some c ...

Github Repositories

Various patches for yiffOS packages. Mirror of https://git.yiffos.gay/Core/patches

patches Various patches for yiffOS packages linux: linux/good_panic_message - Changes the kernel panic message to be better linux/config - Kernel compile config - Partly from Arch Linux linux/package-kernelsh - Kernel packaging script glibc: glibc/fhs-runtime - Patches GLibc for FHS runtime directory compilance - From Linux From Scratch pahole: pahole/buildcmd-prefix-and