oss-sec mailing list archives

Re: [FD] [oss-security] CVE request:Lynx invalid URL parsing with '?'


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Sat, 5 Nov 2016 00:05:35 -0700

Actually, it does parse correctly.  Go read RFC 1738.

IIRC, RFC 3986 "fixes" that, and so does https://url.spec.whatwg.org/.

/mz


Current thread: