buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2016-9179
Component Overview
Vulnerability Overview
Name
CVE-2016-9179
Source
NVD (
link
)
Debian (
link
)
Description
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.
CWEs
CWE-20
Published Date
Dec 22, 2016
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2016/11/04/1
Mailing List
http://www.securityfocus.com/bid/94215
VDB Entry
http://www.openwall.com/lists/oss-security/2016/11/04/1
Mailing List
http://www.securityfocus.com/bid/94215
VDB Entry
Analysis
#
Affected Component
Analysis
lynx
Exploitable
Vulnerability Ratings
#
7.5
other
5
CVSSv2
Others affected component
#
Name
Project
Project Version
Version
Status
lynx
buildroot
master
2.9.2
Exploitable