CVE-2007-5034

ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.
References
Link Resource
http://bugzilla.elinks.cz/show_bug.cgi?id=937
http://secunia.com/advisories/26936
http://secunia.com/advisories/26949
http://secunia.com/advisories/26956
http://secunia.com/advisories/27038
http://secunia.com/advisories/27062
http://secunia.com/advisories/27125
http://secunia.com/advisories/27132
http://www.debian.org/security/2007/dsa-1380
http://www.redhat.com/support/errata/RHSA-2007-0933.html
http://www.securityfocus.com/archive/1/481606/100/0/threaded
http://www.securityfocus.com/bid/25799
http://www.securitytracker.com/id?1018764
http://www.ubuntu.com/usn/usn-519-1
http://www.vupen.com/english/advisories/2007/3278
https://bugs.launchpad.net/ubuntu/+source/elinks/+bug/141018
https://bugzilla.redhat.com/show_bug.cgi?id=297981
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10335
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00079.html
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00335.html
http://bugzilla.elinks.cz/show_bug.cgi?id=937
http://secunia.com/advisories/26936
http://secunia.com/advisories/26949
http://secunia.com/advisories/26956
http://secunia.com/advisories/27038
http://secunia.com/advisories/27062
http://secunia.com/advisories/27125
http://secunia.com/advisories/27132
http://www.debian.org/security/2007/dsa-1380
http://www.redhat.com/support/errata/RHSA-2007-0933.html
http://www.securityfocus.com/archive/1/481606/100/0/threaded
http://www.securityfocus.com/bid/25799
http://www.securitytracker.com/id?1018764
http://www.ubuntu.com/usn/usn-519-1
http://www.vupen.com/english/advisories/2007/3278
https://bugs.launchpad.net/ubuntu/+source/elinks/+bug/141018
https://bugzilla.redhat.com/show_bug.cgi?id=297981
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10335
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00079.html
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00335.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elinks:elinks:*:*:*:*:*:*:*:*
cpe:2.3:a:elinks:elinks:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:36

Type Values Removed Values Added
References () http://bugzilla.elinks.cz/show_bug.cgi?id=937 - () http://bugzilla.elinks.cz/show_bug.cgi?id=937 -
References () http://secunia.com/advisories/26936 - () http://secunia.com/advisories/26936 -
References () http://secunia.com/advisories/26949 - () http://secunia.com/advisories/26949 -
References () http://secunia.com/advisories/26956 - () http://secunia.com/advisories/26956 -
References () http://secunia.com/advisories/27038 - () http://secunia.com/advisories/27038 -
References () http://secunia.com/advisories/27062 - () http://secunia.com/advisories/27062 -
References () http://secunia.com/advisories/27125 - () http://secunia.com/advisories/27125 -
References () http://secunia.com/advisories/27132 - () http://secunia.com/advisories/27132 -
References () http://www.debian.org/security/2007/dsa-1380 - () http://www.debian.org/security/2007/dsa-1380 -
References () http://www.redhat.com/support/errata/RHSA-2007-0933.html - () http://www.redhat.com/support/errata/RHSA-2007-0933.html -
References () http://www.securityfocus.com/archive/1/481606/100/0/threaded - () http://www.securityfocus.com/archive/1/481606/100/0/threaded -
References () http://www.securityfocus.com/bid/25799 - () http://www.securityfocus.com/bid/25799 -
References () http://www.securitytracker.com/id?1018764 - () http://www.securitytracker.com/id?1018764 -
References () http://www.ubuntu.com/usn/usn-519-1 - () http://www.ubuntu.com/usn/usn-519-1 -
References () http://www.vupen.com/english/advisories/2007/3278 - () http://www.vupen.com/english/advisories/2007/3278 -
References () https://bugs.launchpad.net/ubuntu/+source/elinks/+bug/141018 - () https://bugs.launchpad.net/ubuntu/+source/elinks/+bug/141018 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=297981 - () https://bugzilla.redhat.com/show_bug.cgi?id=297981 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10335 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10335 -
References () https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00079.html - () https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00079.html -
References () https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00335.html - () https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00335.html -

Information

Published : 2007-09-21 20:17

Updated : 2024-11-21 00:36


NVD link : CVE-2007-5034

Mitre link : CVE-2007-5034

CVE.ORG link : CVE-2007-5034


JSON object : View

Products Affected

elinks

  • elinks
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor