Skip to main content

Opera Multiple Vulnerabilities

Last Update Date: 1 Feb 2011 Release Date: 28 Jan 2011 5635 Views

RISK: Medium Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities have been identified in Opera, which could be exploited by remote attackers to gain knowledge of sensitive information, perfom unauthorized actions, or compromise a vulnerable system.

  1. An integer truncation error when handling large form inputs, which could be exploited to execute arbitrary code via a malicious web page.
  2. An error when handling internal "opera:" URLs, which could allow clickjacking attacks.
  3. An error when handling certain HTTP responses and redirections, which could allow malicious web pages to load files from a vulnerable system as web page resources.
  4. Due to passwords not being deleted immediately when using "Delete Private Data" and selecting the option to "Clear all email account passwords".
  5. An error when displaying a downloaded file in its folder, which could allow attackers to execute arbitrary code but requires very significant user interaction.
  6. An error when handling "javascript:" URLs in CSS -o-link values.

Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Opera version 11.00 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link