[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Lynx-dev] CVE-2016-9179 (invalid URL parsing with '?')

From: Thomas Dickey
Subject: Re: [Lynx-dev] CVE-2016-9179 (invalid URL parsing with '?')
Date: Tue, 15 Nov 2016 04:07:20 -0500
User-agent: Mutt/1.5.21 (2010-09-15)

On Tue, Nov 15, 2016 at 06:13:59PM +1100, Brian May wrote:
> Thomas Dickey <address@hidden> writes:
> > Interesting enough, when I look at the trace, lynx dev.10 is doing this:
> With lynx 2.8.9dev10-1 from Debian unstable, if I type in:
> lynx 'http://address@hidden/'
> Then I get the following warning that appears on screen for one second
> (easy to miss):
> Alert!: User/password may appear to be a hostname: '' (e.g, 
> '')
> Then it takes me to

yes - and I was using the trace to see if I'd gotten the right host.
The trace is (based on strace...) incorrect.  I'll fix that.

Thomas E. Dickey <address@hidden>

Attachment: signature.asc
Description: Digital signature

reply via email to

[Prev in Thread] Current Thread [Next in Thread]