CVE-2017-1000211

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
17/11/2017
Last modified:
20/04/2025

Description

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lynx_project:lynx:2.8.9:dev15:*:*:*:*:*:*