CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Elinks | Elinks | 0.2.4 (including) | 0.2.4 (including) |
| Elinks | Elinks | 0.3.2 (including) | 0.3.2 (including) |
| Links | Links | 0.96 (including) | 0.96 (including) |
| Lynx | University_of_kansas | 2.8.2_rel1 (including) | 2.8.2_rel1 (including) |
| Lynx | University_of_kansas | 2.8.3 (including) | 2.8.3 (including) |
| Lynx | University_of_kansas | 2.8.3_rel1 (including) | 2.8.3_rel1 (including) |
| Lynx | University_of_kansas | 2.8.4 (including) | 2.8.4 (including) |
| Lynx | University_of_kansas | 2.8.4_rel1 (including) | 2.8.4_rel1 (including) |
| Lynx | University_of_kansas | 2.8.5_dev8 (including) | 2.8.5_dev8 (including) |
| Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
| Red Hat Linux 6.2 | RedHat | * | |
| Red Hat Linux 7.0 | RedHat | * | |
| Red Hat Linux 7.1 | RedHat | * | |
| Red Hat Linux 7.2 | RedHat | * | |
| Red Hat Linux 7.3 | RedHat | * | |
| Red Hat Linux 8.0 | RedHat | * | |
| Red Hat Linux Advanced Workstation 2.1 | RedHat | * |