CVE-2007-5034
Summary
| CVE | CVE-2007-5034 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-09-21 20:17:00 UTC |
| Updated | 2018-10-15 21:40:00 UTC |
| Description | ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ELinks HTTPS POST Request Information Disclosure Weakness | BID | www.securityfocus.com | |
| [SECURITY] Fedora Core 6 Update: elinks-0.11.3-1.fc6 | FEDORA | www.redhat.com | |
| USN-519-1: elinks vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | |
| rPath update for elinks - Advisories - Secunia | SECUNIA | secunia.com | |
| [SECURITY] Fedora 7 Update: elinks-0.11.3-1.fc7 | FEDORA | www.redhat.com | |
| ELinks Proxy CONNECT Weakness - Advisories - Secunia | SECUNIA | secunia.com | |
| 297981 – CVE-2007-5034 elinks reveals POST data to HTTPS proxy [F7] | CONFIRM | bugzilla.redhat.com | |
| Debian -- Security Information -- DSA-1380-1 elinks | DEBIAN | www.debian.org | |
| Fedora update for elinks - Advisories - Secunia | SECUNIA | secunia.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - ELinks May Disclose POST Request Data in Clear Text to Remote Users | SECTRACK | www.securitytracker.com | |
| Support | REDHAT | www.redhat.com | |
| 403 Forbidden | CONFIRM | bugzilla.elinks.cz | |
| Fedora update for elinks - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Red Hat update for elinks - Advisories - Secunia | SECUNIA | secunia.com | |
| Bug #141018 “ELinks reveals POST data to HTTPS proxy” : Bugs : elinks package : Ubuntu | CONFIRM | bugs.launchpad.net | |
| Ubuntu update for elinks - Advisories - Secunia | SECUNIA | secunia.com | |
| Debian update for elinks - Advisories - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.