CVE-2007-5034
Summary
| CVE | CVE-2007-5034 |
|---|---|
| State | PUBLISHED |
| Assigner | canonical |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-21 20:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ubuntu update for elinks - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for elinks - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for elinks - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| ELinks HTTPS POST Request Information Disclosure Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bug #141018 “ELinks reveals POST data to HTTPS proxy” : Bugs : elinks package : Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| 297981 – CVE-2007-5034 elinks reveals POST data to HTTPS proxy [F7] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Debian -- Security Information -- DSA-1380-1 elinks | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora Core 6 Update: elinks-0.11.3-1.fc6 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for elinks - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-519-1: elinks vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| rPath update for elinks - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - ELinks May Disclose POST Request Data in Clear Text to Remote Users | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Fedora update for elinks - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 7 Update: elinks-0.11.3-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.elinks.cz | |
| ELinks Proxy CONNECT Weakness - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.