The lynx text-mode web browser has a problem understanding invalid
html involving the TEXTAREA tag. An infinite loop can happen, resulting
in a denial of service.
Posted Jun 9, 2006 14:24 UTC (Fri) by kingdon (subscriber, #4526)
[Link]
The DSA-1085-1 alert (but not the other two) also refers to a more serious sounding issue:
CAN-2005-3120
Ulf Härnhammar discovered a buffer overflow that can be remotely
exploited. During the handling of Asian characters when connecting
to an NNTP server lynx can be tricked to write past the boundary
of a buffer which can lead to the execution of arbitrary code.