CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.
| Software | From | Fixed in |
|---|---|---|
| elinks / elinks | 0.3.2 | 0.3.2.x |
| university_of_kansas / lynx | 2.8.4 | 2.8.4.x |
| university_of_kansas / lynx | 2.8.4_rel1 | 2.8.4_rel1.x |
| university_of_kansas / lynx | 2.8.3 | 2.8.3.x |
| university_of_kansas / lynx | 2.8.5_dev8 | 2.8.5_dev8.x |
| university_of_kansas / lynx | 2.8.2_rel1 | 2.8.2_rel1.x |
| links / links | 0.96 | 0.96.x |
| university_of_kansas / lynx | 2.8.3_rel1 | 2.8.3_rel1.x |
| elinks / elinks | 0.2.4 | 0.2.4.x |