Bug#744799: elinks follows HTTP redirects to file:// URLs

2014-05-02 Thread Kalle Olavi Niemitalo
Jakub Wilk jw...@debian.org writes: elinks follows HTTP 302 redirects to file:// URLs. This can cause information disclosure or, if protocol.file.allow_special_files is enabled, denial of service: If a local user is running ELinks and getting the output to a terminal, then ELinks will display

Bug#744799: elinks follows HTTP redirects to file:// URLs

2014-04-14 Thread Jakub Wilk
Package: elinks Version: 0.12~pre6-4 Severity: minor Tags: security elinks follows HTTP 302 redirects to file:// URLs. This can cause information disclosure or, if protocol.file.allow_special_files is enabled, denial of service: $ elinks -dump