PT-2007-6139 · Elinks+1 · Elinks+1

Published

2007-09-21

·

Updated

2018-10-15

·

CVE-2007-5034

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ELinks versions prior to 0.11.3
Description The issue allows remote attackers to sniff sensitive data that would have been protected by TLS when sending a POST request for an https URL. This occurs because the body and content headers of the POST request are appended to the CONNECT request in cleartext. The issue is specific to scenarios where a proxy is defined for https.
Recommendations For versions prior to 0.11.3, update to version 0.11.3 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5034
DSA-1380-1
RHSA-2007:0933
RHSA-2007_0933

Affected Products

Elinks
Red Hat