CVE Vulnerabilities

CVE-2002-1405

Published: Feb 19, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Affected Software

NameVendorStart VersionEnd Version
ElinksElinks0.2.4 (including)0.2.4 (including)
ElinksElinks0.3.2 (including)0.3.2 (including)
LinksLinks0.96 (including)0.96 (including)
LynxUniversity_of_kansas2.8.2_rel1 (including)2.8.2_rel1 (including)
LynxUniversity_of_kansas2.8.3 (including)2.8.3 (including)
LynxUniversity_of_kansas2.8.3_rel1 (including)2.8.3_rel1 (including)
LynxUniversity_of_kansas2.8.4 (including)2.8.4 (including)
LynxUniversity_of_kansas2.8.4_rel1 (including)2.8.4_rel1 (including)
LynxUniversity_of_kansas2.8.5_dev8 (including)2.8.5_dev8 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 6.2RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*

References