Show Table of Contents
4.25. elinks
An updated elinks package that fixes one security issue is now available for Red Hat Enterprise Linux 5 and 6.
The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link associated with the description below.
ELinks is a text-based web browser. ELinks does not display any images, but it does support frames, tables, and most other HTML tags.
Security Fix
- CVE-2012-4545
- It was found that ELinks performed client credentials delegation during the client-to-server GSS security mechanisms negotiation. A rogue server could use this flaw to obtain the client's credentials and impersonate that client to other servers that are using GSSAPI.
This issue was discovered by Marko Myllynen of Red Hat.
All ELinks users are advised to upgrade to this updated package, which contains a backported patch to resolve the issue.

Where did the comment section go?
Red Hat's documentation publication system recently went through an upgrade to enable speedier, more mobile-friendly content. We decided to re-evaluate our commenting platform to ensure that it meets your expectations and serves as an optimal feedback mechanism. During this redesign, we invite your input on providing feedback on Red Hat documentation via the discussion platform.