ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that would have been protected by TLS. NOTE: this issue only occurs when a proxy is defined for https.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: canonical

Published: 2007-09-21T20:00:00

Updated: 2018-10-15T20:57:01

Reserved: 2007-09-21T00:00:00


Link: CVE-2007-5034

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2007-09-21T20:17:00.000

Modified: 2018-10-15T21:40:03.380


Link: CVE-2007-5034

JSON object: View

cve-icon Redhat Information

No data.

CWE