SECURITY: Fedora 34 Update: lynx-2.8.9-13.fc34
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-f59bda7d94
2021-09-08 15:05:54.167624
--------------------------------------------------------------------------------
Name : lynx
Product : Fedora 34
Version : 2.8.9
Release : 13.fc34
URL : http://lynx.browser.org/
Summary : A text-based Web browser
Description :
Lynx is a text-based Web browser. Lynx does not display any images,
but it does support frames, tables, and most other HTML tags. One
advantage Lynx has over graphical browsers is speed; Lynx starts and
exits quickly and swiftly displays web pages.
--------------------------------------------------------------------------------
Update Information:
- fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Aug 31 2021 Kamil Dudka - 2.8.9-13
- fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)
* Thu Jul 22 2021 Fedora Release Engineering - 2.8.9-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1994998 - CVE-2021-38165 lynx: Disclosure of HTTP authentication credentials via SNI data
https://bugzilla.redhat.com/show_bug.cgi?id=1994998
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-f59bda7d94' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
A lynx security update has been released for Fedora 34.