Medium severity5.3NVD Advisory· Published Nov 17, 2017· Updated May 13, 2026
CVE-2017-1000211
CVE-2017-1000211
Description
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lynx.invisible-island.net/current/CHANGES.htmlnvdRelease NotesVendor Advisory
- github.com/ThomasDickey/lynx-snapshots/commit/280a61b300a1614f6037efc0902ff7ecf17146e9nvdRelease NotesThird Party Advisory
- www.securityfocus.com/bid/102180nvd
- lists.debian.org/debian-lts-announce/2017/11/msg00021.htmlnvd
News mentions
0No linked articles in our index yet.