CVE-2012-4545: Medium severity wp links page vulnerability
The httpnegotiatecreatecontext function in protocol/http/httpnegotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4545?
CVE-2012-4545 is considered a moderate severity vulnerability due to the risk of credential delegation.
How do I fix CVE-2012-4545?
To fix CVE-2012-4545, upgrade ELinks to version 0.12pre6 or later, which addresses the issue.
What are the implications of exploiting CVE-2012-4545?
Exploiting CVE-2012-4545 allows remote servers to authenticate as the client using delegated credentials, potentially compromising security.
Which versions of ELinks are affected by CVE-2012-4545?
CVE-2012-4545 affects ELinks versions 0.12-pre1 through 0.12-pre5.
Is CVE-2012-4545 a local or remote vulnerability?
CVE-2012-4545 is a remote vulnerability that can be exploited by attackers without physical access to the system.