it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4953-1] lynx security update
- Date: Tue, 10 Aug 2021 04:10:49 +0000
- Authentication-results: mail02.piratenpartei.de; dkim=none; spf=none (mail02.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/E1mDJ6H-0004iG-9e AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=mWyMe4tRrpIOLMmhM+kU7Xo/Pew8sivofninDU0ly2A=; b=rQ T9sMctQ6OSlMpceSYkH9hyJO4NW10fmZwbks/nIuT/h/SRwTcl9BQ7yplTlVw094bw2cNTZJU7HYt hBsFD5v6dX5gtt3QwI4R51r+RrrtoezHOjC3UnQxFtUa3ZU39MN9lqAbTt9mp5A6bKb7SkIQfjN9o E78h1lna8VkS2of0E97vHrjgzkw19jGR9fZHMggi3F6HcnFB23lw+5oHYCuV4TGH/wyUdFWjG7Wjf Vf52bq7dNtij59TvX5z+Ri2NMkElbPefeiyFDkBcFa77+t5rNOYNr5Oyo06nSLgblmtGXxGw7ptFz Eog6TJp3gmsCe+pFU/tOhri14rl58p0Q==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Tue, 10 Aug 2021 04:11:06 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <DLeeuh_tD5G.A.7eB.axfEhB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4953-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 10, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : lynx
CVE ID : CVE-2021-38165
Debian Bug : 991971
Thorsten Glaser and Axel Beckert reported that lynx, a non-graphical
(text-mode) web browser, does not properly handle the userinfo
subcomponent of a URI, which can lead to leaking of credential in
cleartext in SNI data.
For the stable distribution (buster), this problem has been fixed in
version 2.8.9rel.1-3+deb10u1.
We recommend that you upgrade your lynx packages.
For the detailed security status of lynx please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/lynx
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmER/AxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QDfg//QnGHbsACdZaIGyOrTrsoXXHowm44Jsctzvtrw4aK7YFwUNhXc4vqBRSB
Ql7y24qhIweUvooPKedSbUZYSmavBSD/UtCN07NckhWX/SJHCSv9l2tS1vMhdxyz
pUCY4kEKTifnCvJO2/ReFMr4rxBPrK5XhQxZuYLDCwhraN7qFRFBs2Ogy1X2PU24
V+BtvmYOvr03gQCr21ps5HRsXQfCVfCcPNumzP12ziRVbr2ebZSHMBiNDAU7Q/rq
oXhQgIkUWoA+bPBDeDNA6ay46BUPyjYaeb4kiWkduJ5hbi4E2Af1HGTZEvMgb6f8
Ozckln7JCh8bgjvPeeoAKBEv6OPcZZ4vT0VX40yoW332KOkqA4d/xM7kdTBPCSpa
9Cu4l1886MK06xvv/ZUXRvXbCgaRsyhh1N6WL6xjdfvKN4JB/sjeXRnVLleTtUyy
RYWzYHvyjOBSiB+W/TNBGucstSIUEha8OiTJwXMuQc+0nv/dPYmtGjVBjG+8wB0F
h7P/nJpsofAew3TB9Dn1ni7w5yo2z3Mea2ea9wbIYWJnPRYVNRdIemq/l0Z6Ukna
6Hzfdx9bCN5g2InIHwPu1nCf2HOprrssETCEHuz2g5eKl6PDO+Pl3mfsT1pCX72N
+BjzgkSGEw1kUnfW9fzLWrUbEJaEkKFuouGoOPgdb8nmHBO9Kt0=
=IuY3
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4953-1] lynx security update, Salvatore Bonaccorso, 10.08.2021
Archiv bereitgestellt durch MHonArc 2.6.24.