Package: elinks
Severity: normal
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for elinks.

CVE-2007-5034[0]:
| ELinks before 0.11.3, when sending a POST request for an https URL,
| appends the body and content headers of the POST request to the
| CONNECT request in cleartext, which allows remote attackers to sniff
| sensitive data that would have been protected by TLS.  NOTE: this
| issue only occurs when a proxy is defined for https.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

Since this just happens when a proxy is used for https I set 
the severity to normal.

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5034

Kind regards
Nico

-- 
Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgp0nuihS44sY.pgp
Description: PGP signature

Reply via email to