Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
{
"binaries": [
{
"binary_version": "2.8.9dev8-4ubuntu1+esm2",
"binary_name": "lynx"
},
{
"binary_version": "2.8.9dev8-4ubuntu1+esm2",
"binary_name": "lynx-common"
},
{
"binary_version": "2.8.9dev8-4ubuntu1+esm2",
"binary_name": "lynx-cur"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}