SciLinux: CVE-2007-5034 elinks SL5.x, SL4.x i386/x86_64
Summary
Date: Thu, 4 Oct 2007 11:16:24 -0500Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for elinks on SL5.x, SL4.x i386/x86_64Comments: To: scientific Synopsis: Moderate: elinks security updateCVE Names: CVE-2007-5034Details:An information disclosure flaw was found in the way ELinks passes httpsPOST data to a proxy server. POST data sent via a proxy to an https site isnot properly encrypted by ELinks, possibly allowing the disclosure ofsensitive information. (CVE-2007-5034)SL4.x SRPMS: elinks-0.9.2-3.3.5.2.src.rpm i386: elinks-0.9.2-3.3.5.2.i386.rpm x86_64: elinks-0.9.2-3.3.5.2.x86_64.rpmSL5.x SRPMS: elinks-0.11.1-5.1.0.1.el5.src.rpm i386: elinks-0.11.1-5.1.0.1.el5.i386.rpm x86_64: elinks-0.11.1-5.1.0.1.el5.x86_64.rpm-Connie Sieh-Troy Dawson