Medium severity5.3NVD Advisory· Published Aug 7, 2021· Updated Jun 17, 2026
CVE-2021-38165
CVE-2021-38165
Description
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- Lynx/Lynxdescription
Patches
Vulnerability mechanics
References
13- www.openwall.com/lists/oss-security/2021/08/07/11nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/08/07/12nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/08/07/9nvdMailing ListThird Party Advisory
- bugs.debian.org/991971nvdIssue TrackingThird Party Advisory
- github.com/w3c/libwww/blob/f010b4cc58d32f34b162f0084fe093f7097a61f0/Library/src/HTParse.cnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/08/msg00010.htmlnvdMailing ListThird Party Advisory
- lynx.invisible-island.net/current/CHANGES.htmlnvdRelease NotesThird Party Advisory
- www.debian.org/security/2021/dsa-4953nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2021/08/07/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/08/07/11nvdMailing List
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7YMUHFJJWTZ6HBHTYXVDPNZINGGURHDW/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K6PZF7JNTFCOJ62HXZG4Q2NEHSZ6IO2V/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VKNK7GQBJBUBMJVNKVC7RTCYWUYMFJQW/nvd
News mentions
0No linked articles in our index yet.