CVE-2021-38165 - Lynx Project Lynx and Debian Debian Linux

Critical 7.5

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

Affected software

Lynx Project Lynx

Debian Debian Linux

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.