Unrated severityNVD Advisory· Published Feb 19, 2003· Updated Apr 16, 2026
CVE-2002-1405
CVE-2002-1405
Description
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.
Affected products
9cpe:2.3:a:university_of_kansas:lynx:2.8.2_rel1:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:university_of_kansas:lynx:2.8.2_rel1:*:*:*:*:*:*:*
- cpe:2.3:a:university_of_kansas:lynx:2.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:university_of_kansas:lynx:2.8.3_rel1:*:*:*:*:*:*:*
- cpe:2.3:a:university_of_kansas:lynx:2.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:university_of_kansas:lynx:2.8.4_rel1:*:*:*:*:*:*:*
- cpe:2.3:a:university_of_kansas:lynx:2.8.5_dev8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.debian.org/security/2002/dsa-210nvdPatchVendor Advisory
- www.iss.net/security_center/static/9887.phpnvdPatchVendor Advisory
- ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-049.0.txtnvd
- marc.infonvd
- marc.infonvd
- www.mandrakesoft.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2003-029.htmlnvd
- www.redhat.com/support/errata/RHSA-2003-030.htmlnvd
- www.securityfocus.com/bid/5499nvd
- www.trustix.net/errata/misc/2002/TSL-2002-0085-lynx-ssl.asc.txtnvd
News mentions
0No linked articles in our index yet.