Oval Definition:oval:com.redhat.rhsa:def:20091471
Revision Date:2009-10-01Version:641
Title:RHSA-2009:1471: elinks security update (Important)
Description:ELinks is a text-based Web browser. ELinks does not display any images, but it does support frames, tables, and most other HTML tags.

  • An off-by-one buffer overflow flaw was discovered in the way ELinks handled its internal cache of string representations for HTML special entities. A remote attacker could use this flaw to create a specially-crafted HTML file that would cause ELinks to crash or, possibly, execute arbitrary code when rendered. (CVE-2008-7224)

  • It was discovered that ELinks tried to load translation files using relative paths. A local attacker able to trick a victim into running ELinks in a folder containing specially-crafted translation files could use this flaw to confuse the victim via incorrect translations, or cause ELinks to crash and possibly execute arbitrary code via embedded formatting sequences in translated messages. (CVE-2007-2027)

    All ELinks users are advised to upgrade to this updated package, which contains backported patches to resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-2027
    CVE-2008-7224
    RHSA-2009:1471
    RHSA-2009:1471-01
    RHSA-2009:1471-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND elinks is earlier than 0:0.9.2-4.el4_8.1
  • AND elinks is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND elinks is earlier than 0:0.11.1-6.el5_4.1
  • AND elinks is signed with Red Hat redhatrelease2 key
  • BACK