Return to CVE list

CVE-2007-5034

4.3
Medium

CVE-2007-5034

security@ubuntu.com
Modified

Description

ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.

Exploits

No known exploits found for this CVE.

Search Exploit-DB

References

af854a3a-2127-422b-91ae-364da2661108
http://bugzilla.elinks.cz/show_bug.cgi?id=937
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26936
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26949
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26956
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27038
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27062
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27125
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27132
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2007/dsa-1380
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/25799
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1018764
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-519-1
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/3278
af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=297981