MEDIUM · 5.0

CVE-2002-1405

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carr...

Vulnerability Description

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
ElinksElinks0.2.4
LinksLinks0.96
University Of KansasLynx2.8.2_rel1

References

FAQ

What is CVE-2002-1405?

CVE-2002-1405 is a vulnerability with a CVSS score of 5.0 (MEDIUM). CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carr...

How severe is CVE-2002-1405?

CVE-2002-1405 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1405?

Check the references section above for vendor advisories and patch information. Affected products include: Elinks Elinks, Links Links, University Of Kansas Lynx.