Debian Security Advisory DSA 210-1 (lynx, lynx-ssl)

Summary
The remote host is missing an update to lynx, lynx-ssl announced via advisory DSA 210-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20210-1
Insight
lynx (a text-only web browser) did not properly check for illegal characters in all places, including processing of command line options, which could be used to insert extra HTTP headers in a request. For Debian GNU/Linux 2.2/potato this has been fixed in version 2.8.3-1.1 of the lynx package and version 2.8.3.1-1.1 of the lynx-ssl package. For Debian GNU/Linux 3.0/woody this has been fixed in version 2.8.4.1b-3.2 of the lynx package and version 1:2.8.4.1b-3.1 of the lynx-ssl package.