Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.

Bug 152830

Summary: Links Malformed Table Denial of Service
Product: [Retired] Fedora Legacy Reporter: John Dalbec <jpdalbec>
Component: Package requestAssignee: Fedora Legacy Bugs <bugs>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: low    
Version: unspecifiedCC: pekkas
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://www.securityfocus.com/archive/1/378632
Whiteboard: LEGACY, DEFER
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-08-30 19:57:23 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description David Lawrence 2005-03-30 23:28:57 UTC
04.42.12 CVE: Not Available
Platform: Unix
Title: Links Malformed Table Denial of Service
Description: Links is vulnerable to a denial of service issue when
handling specially crafted HTML tables. Links versions 0.99 and
earlier are known to be vulnerable.
Ref: http://www.securityfocus.com/archive/1/378632



------- Additional Comments From pekkas@netcore.fi 2004-12-20 11:13:09 ----

For more info, see:

http://bugzilla.elinks.or.cz/show_bug.cgi?id=546
http://linuxfromscratch.org/pipermail/elinks-users/2004-November/000736.html
 (i.e., there may be other problems which might be worth checking, e.g., the
cookie domain security checking.)

The elinks bugs have not been entered in RHL bugzilla, nor exist in many other
vendors' bugzillas, like Debian.

It might also be possible to just bump up the version to 0.9.3, but let's try to
avoid that if reasonable..



------- Bug moved to this database by dkl@redhat.com 2005-03-30 18:28 -------

This bug previously known as bug 2213 at https://bugzilla.fedora.us/
https://bugzilla.fedora.us/show_bug.cgi?id=2213
Originally filed under the Fedora Legacy product and Package request component.

Unknown priority P3. Setting to default priority "normal".
Unknown platform PC. Setting to default platform "All".
Unknown severity minor. Setting to default severity "normal".
Setting qa contact to the default for this product.
   This bug either had no qa contact or an invalid one.



Comment 1 Pekka Savola 2005-11-16 13:20:16 UTC
This doesn't seem to be important enough to fix just on its own, so mark it DEFER.

Comment 2 Jesse Keating 2007-08-30 19:57:23 UTC
Fedora Legacy project has ended.  These will not be fixed by Fedora Legacy.