Submitted by KeesCook on Tue, 2007-09-25 21:51
Referenced CVEs:
CVE-2007-5034
Description:
===========================================================
Ubuntu Security Notice USN-519-1 September 25, 2007
elinks vulnerability
CVE-2007-5034
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
elinks 0.10.6-1ubuntu3.2
Ubuntu 6.10:
elinks 0.11.1-1ubuntu2.2
Ubuntu 7.04:
elinks 0.11.1-1.2ubuntu2.2
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Kalle Olavi Niemitalo discovered that if elinks makes a POST request
to an HTTPS URL through a proxy, information may be sent in clear-text
between elinks and the proxy. Attackers with access to the network
could steal sensitive information (such as passwords).


