LWN.net Logo

elinks: remote data sniffing

Package(s):elinks CVE #(s):CVE-2007-5034
Created:September 25, 2007 Updated:October 9, 2007
Description: ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.
Alerts:
Fedora FEDORA-2007-710 2007-10-08
rPath rPSA-2007-0209-1 2007-10-05
Red Hat RHSA-2007:0933-01 2007-10-03
Debian DSA-1380-1 2007-10-02
Ubuntu USN-519-1 2007-09-25
Fedora FEDORA-2007-2224 2007-09-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds