Lynx CRLF injection vulnerability
[Posted August 28, 2002 by dennis]
Ulf Harnhammar
reports a CRLF injection
vulnerability in Lynx which may be used to
break out of restricted realms
and communicate with other
types of servers than HTTP servers.
The problem is also present in
links and elinks.
Both the links and the elinks maintainers were notified on the 13th of
August, but as they both live in the Czech Republic, they have been
affected by the recent floods in Central Europe. Because of this dilemma,
it is possible that they would appreciate a patch for this security hole
from some experienced C programmer.
(
Log in to post comments)