Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-5034
Description:ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.
Test IDs: 1.3.6.1.4.1.25623.1.0.62185   1.3.6.1.4.1.25623.1.0.861218   1.3.6.1.4.1.25623.1.0.122656   1.3.6.1.4.1.25623.1.0.59207   1.3.6.1.4.1.25623.1.0.58640   1.3.6.1.4.1.25623.1.0.861580   1.3.6.1.4.1.25623.1.0.58955   1.3.6.1.4.1.25623.1.0.59712   1.3.6.1.4.1.25623.1.0.840168  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-5034
BugTraq ID: 25799
http://www.securityfocus.com/bid/25799
Bugtraq: 20071005 rPSA-2007-0209-1 elinks (Google Search)
http://www.securityfocus.com/archive/1/481606/100/0/threaded
Debian Security Information: DSA-1380 (Google Search)
http://www.debian.org/security/2007/dsa-1380
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00335.html
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00079.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10335
RedHat Security Advisories: RHSA-2007:0933
http://www.redhat.com/support/errata/RHSA-2007-0933.html
http://www.securitytracker.com/id?1018764
http://secunia.com/advisories/26936
http://secunia.com/advisories/26949
http://secunia.com/advisories/26956
http://secunia.com/advisories/27038
http://secunia.com/advisories/27062
http://secunia.com/advisories/27125
http://secunia.com/advisories/27132
http://www.ubuntu.com/usn/usn-519-1
http://www.vupen.com/english/advisories/2007/3278




© 1998-2025 E-Soft Inc. All rights reserved.