CVE-2012-4545
Published: 3 January 2013
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.
Priority
Status
Package | Release | Status |
---|---|---|
elinks Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Ignored
(end of life)
|
|
quantal |
Ignored
(end of life)
|
|
raring |
Not vulnerable
(0.12~pre5-9ubuntu1)
|
|
saucy |
Not vulnerable
(0.12~pre5-9ubuntu1)
|
|
trusty |
Does not exist
(trusty was not-affected [0.12~pre5-9ubuntu1])
|
|
upstream |
Released
(0.12~pre5-9)
|
|
utopic |
Not vulnerable
(0.12~pre5-9ubuntu1)
|
|
vivid |
Not vulnerable
(0.12~pre5-9ubuntu1)
|
|
wily |
Not vulnerable
(0.12~pre5-9ubuntu1)
|
|
xenial |
Not vulnerable
(0.12~pre5-9ubuntu1)
|
|
yakkety |
Not vulnerable
(0.12~pre5-9ubuntu1)
|
|
zesty |
Not vulnerable
(0.12~pre5-9ubuntu1)
|