Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38165

Опубликовано: 07 авг. 2021
Источник: redhat
CVSS3: 5.3

Описание

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

A flaw was found in the way lynx parsed URLs with userinfo part containing authentication credentials. These credentials were included in the Server Name Indication (SNI) TLS extension data and sent unencrypted during the TLS connection handshake. This could lead to exposure of authentication credentials to attackers able to eavesdrop on network connection between the lynx browser and the server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6lynxNot affected
Red Hat Enterprise Linux 7lynxOut of support scope
Red Hat Enterprise Linux 9lynxNot affected
Red Hat Enterprise Linux 8lynxFixedRHSA-2022:212910.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1994998lynx: Disclosure of HTTP authentication credentials via SNI data

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

CVSS3: 5.3
nvd
больше 4 лет назад

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

CVSS3: 5.3
debian
больше 4 лет назад

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, whic ...

github
больше 3 лет назад

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

CVSS3: 5.3
fstec
больше 4 лет назад

Уязвимость подкомпонента userinfo текстового веб-браузера Lynx, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным

5.3 Medium

CVSS3