LWN.net Logo

Lynx CRLF injection vulnerability

Ulf Harnhammar reports a CRLF injection vulnerability in Lynx which may be used to break out of restricted realms and communicate with other types of servers than HTTP servers.

The problem is also present in links and elinks.

Both the links and the elinks maintainers were notified on the 13th of August, but as they both live in the Czech Republic, they have been affected by the recent floods in Central Europe. Because of this dilemma, it is possible that they would appreciate a patch for this security hole from some experienced C programmer.

(Log in to post comments)

Copyright © 2002, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds