CVE Vulnerabilities

CVE-2002-1405

Published: Feb 19, 2003 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Affected Software

Name Vendor Start Version End Version
Elinks Elinks 0.2.4 (including) 0.2.4 (including)
Elinks Elinks 0.3.2 (including) 0.3.2 (including)
Links Links 0.96 (including) 0.96 (including)
Lynx University_of_kansas 2.8.2_rel1 (including) 2.8.2_rel1 (including)
Lynx University_of_kansas 2.8.3 (including) 2.8.3 (including)
Lynx University_of_kansas 2.8.3_rel1 (including) 2.8.3_rel1 (including)
Lynx University_of_kansas 2.8.4 (including) 2.8.4 (including)
Lynx University_of_kansas 2.8.4_rel1 (including) 2.8.4_rel1 (including)
Lynx University_of_kansas 2.8.5_dev8 (including) 2.8.5_dev8 (including)

References