PT-2003-1028 · Lynx · Lynx

Published

2003-01-28

·

Updated

2016-10-18

·

CVE-2002-1405

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Lynx versions 2.8.4 and earlier
Description The issue allows remote attackers to inject false HTTP headers into an HTTP request, potentially leading to the disruption of protected information integrity. This can be achieved via a URL containing encoded carriage return, line feed, and other whitespace characters. The exploitation of this issue can be performed remotely.
Recommendations For Lynx versions 2.8.4 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03456
BDU:2015-07925
BDU:2015-07926
CVE-2002-1405
DSA-210

Affected Products

Lynx