package/lynx: add security patch for CVE-2021-38165
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 21 Sep 2021 09:32:49 +0000 (11:32 +0200)
committerArnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
Wed, 22 Sep 2021 19:20:02 +0000 (21:20 +0200)
commit5bb9d79f276551c8fb7a774d8c7bd0f47a9e9809
treeac9cc5770b21213056b326f7272f5e3350ab28ce
parent69e4493fb1e676f29347701a58f67d81bd76b1eb
package/lynx: add security patch for CVE-2021-38165

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which
allows remote attackers to discover cleartext credentials because they may
appear in SNI data.

https://lists.nongnu.org/archive/html/lynx-dev/2021-08/msg00002.html

Upstream unfortunately does not provide a public VCS (only source
snapshots), so fetch the security patch from Debian.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Arnout Vandecappelle (Essensium/Mind) <arnout@mind.be>
package/lynx/lynx.hash
package/lynx/lynx.mk