CVE-2012-4545

ELinks <0.12pre6 - Auth Bypass

Title source: llm

Description

The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.

Scores

EPSS 0.0047
EPSS Percentile 64.4%

Classification

CWE
CWE-287
Status draft

Affected Products (5)

elinks/elinks
elinks/elinks
elinks/elinks
elinks/elinks
elinks/elinks

Timeline

Published Jan 03, 2013
Tracked Since Feb 18, 2026