Lynx Command Line URL CRLF Injection Vulnerability

BID:5499

Info

Lynx Command Line URL CRLF Injection Vulnerability

Bugtraq ID: 5499
Class: Input Validation Error
CVE: CVE-2002-1405
Remote: Yes
Local: No
Published: Aug 19 2002 12:00AM
Updated: Jul 11 2009 03:56PM
Credit: Discovery credited to Ulf Harnhammar <[email protected]>.
Vulnerable: University of Kansas Lynx 2.8.5 dev.8
+ MandrakeSoft Multi Network Firewall 2.0
+ MandrakeSoft Single Network Firewall 7.2
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
+ Mandriva Linux Mandrake 7.2
University of Kansas Lynx 2.8.4 rel.1
University of Kansas Lynx 2.8.4
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Debian Linux 3.0
+ Redhat Linux for iSeries 7.1
+ Redhat Linux for pSeries 7.1
+ Sun Linux 5.0.6
+ Trustix Secure Linux 1.5
+ Trustix Secure Linux 1.2
+ Trustix Secure Linux 1.1
University of Kansas Lynx 2.8.3 rel.1
University of Kansas Lynx 2.8.3
+ Debian Linux 2.2
University of Kansas Lynx 2.8.2 rel.1
Twibright Labs Links 0.96
ELinks ELinks 0.3.2
ELinks ELinks 0.2.4
Not Vulnerable: ELinks ELinks 0.4 pre15

Discussion

Lynx Command Line URL CRLF Injection Vulnerability

A CRLF injection vulnerability has been reported for Lynx that may allow an attacker to include extra HTTP headers when viewing web pages. If Lynx is called from the command line, carriage return and line feed (CRLF) characters may be included in the specified URL. These characters are not escaped when the input is used to construct a HTTP request.

Exploitation of this flaw may allow an attacker to inject additional HTTP headers into a request. Abuse of the 'Host' header may cause the request to be served as if made to a different domain, possibly providing the attacker with more control over the content returned.

This vulnerability has been reported for Lynx versions 2.8.4rel.1, 2.8.5dev.8, 2.8.3rel.1 and 2.8.2rel.1. It is not known whether other versions are affected.

*** Links 0.9.6 and ELinks have also been reported as being vulnerable. Some versions of Links and ELinks URL encode space characters so an attacker needs to use tab characters, instead of spaces, to exploit the issue on these browsers.

Exploit / POC

Lynx Command Line URL CRLF Injection Vulnerability

The following exploit has been provided by Ulf Harnhammar &lt;[email protected]&gt;:

Solution / Fix

Lynx Command Line URL CRLF Injection Vulnerability

Solution:
ELinks 0.4pre15 is not vulnerable to this issue. Users of ELinks are urged to download and install the newest version of ELinks:

Conectiva has released an advisory (CLA-2003:720) to address this issue. Please see the attached advisory for further details regarding applying fixes. Fixes are linked below.

SCO has released a security advisory. Fixes for OpenLinux are available.

The Lynx patch is now available at a different location.

Debian has released an advisory (Debian Security Advisory DSA-210-1) which contains fixes. Please see the attached advisory for more details on obtaining fixes.

Red Hat has release advisory RHSA-2003:029-06 to address this issue.

OpenPKG has made fixes versions of their lynx package available. See referenced advisory for more details.

Sun has released a fix for Sun Linux 5.0.6.

The following fixes are available:


ELinks ELinks 0.2.4

ELinks ELinks 0.3.2

University of Kansas Lynx 2.8.3

University of Kansas Lynx 2.8.4

University of Kansas Lynx 2.8.4 rel.1

University of Kansas Lynx 2.8.5 dev.8

References

Lynx Command Line URL CRLF Injection Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report