Lynx Browser Certificate Verification Security Bypass Vulnerability
BID:56795
Info
Lynx Browser Certificate Verification Security Bypass Vulnerability
| Bugtraq ID: | 56795 |
| Class: | Design Error |
| CVE: |
CVE-2012-5821 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2012 12:00AM |
| Updated: | Apr 10 2013 12:48PM |
| Credit: | Reported at the ACM CCS 2012 conference |
| Vulnerable: |
University of Kansas Lynx 0 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 |
| Not Vulnerable: | |
Discussion
Lynx Browser Certificate Verification Security Bypass Vulnerability
Lynx browser is prone to a security-bypass vulnerability because the application fails to properly verify SSL certificates from a server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid further attacks.
Lynx browser is prone to a security-bypass vulnerability because the application fails to properly verify SSL certificates from a server.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which will aid further attacks.
Exploit / POC
Lynx Browser Certificate Verification Security Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Lynx Browser Certificate Verification Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Lynx Browser Certificate Verification Security Bypass Vulnerability
References:
References:
- Lynx Homepage (Lynx)