Opera Web Browser Remote Window Hijacking Vulnerability
BID:11856
Info
Opera Web Browser Remote Window Hijacking Vulnerability
| Bugtraq ID: | 11856 |
| Class: | Design Error |
| CVE: |
CVE-2004-1157 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2004 12:00AM |
| Updated: | Jul 12 2009 08:07AM |
| Credit: | Discovery of this issue is credited to Secunia Research. |
| Vulnerable: |
S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Opera Software Opera Web Browser 8.0 Opera Software Opera Web Browser 7.54 Gentoo Linux |
| Not Vulnerable: |
Opera Software Opera Web Browser 8.0 1 |
Discussion
Opera Web Browser Remote Window Hijacking Vulnerability
Opera Web Browser is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
Opera Web Browser 7.54 is reported vulnerable to this issue, however, it is possible that other versions are affected as well.
Opera Web Browser is reported prone to a vulnerability that may allow a Web site to hijack the contents of a trusted window. This issue may allow a remote attacker to carry out phishing style attacks.
This issue arises as a user visits a malicious site and follows a link to a trusted site. Once the link to the trusted site is followed, the victim must open a pop up window from the trusted site that can be influenced by the attacker's site.
If successful, the contents of the target site's window can be spoofed resulting in phishing style attacks.
Opera Web Browser 7.54 is reported vulnerable to this issue, however, it is possible that other versions are affected as well.
Exploit / POC
Opera Web Browser Remote Window Hijacking Vulnerability
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_window_injection_vulnerability_test/
Solution / Fix
Opera Web Browser Remote Window Hijacking Vulnerability
Solution:
The vendor has released fixes to address this and other issues.
Gentoo has released an advisory (GLSA 200502-17) and an updated eBuild to address this and other issues in the Opera Web Browser. This update can be installed by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/opera-7.54-r3"
The vendor has released Opera 8.01 to address this issue in Opera 8.0.
SUSE has released security announcement SUSE-SA:2005:034 addressing this issue. Please see the referenced advisory for further information.
Opera Software Opera Web Browser 7.54
Opera Software Opera Web Browser 8.0
Solution:
The vendor has released fixes to address this and other issues.
Gentoo has released an advisory (GLSA 200502-17) and an updated eBuild to address this and other issues in the Opera Web Browser. This update can be installed by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/opera-7.54-r3"
The vendor has released Opera 8.01 to address this issue in Opera 8.0.
SUSE has released security announcement SUSE-SA:2005:034 addressing this issue. Please see the referenced advisory for further information.
Opera Software Opera Web Browser 7.54
-
Opera Software Opera 7.54u2
http://www.opera.com/download/
Opera Software Opera Web Browser 8.0
-
Opera Software Opera 8.01
http://www.opera.com/download/
References
Opera Web Browser Remote Window Hijacking Vulnerability
References:
References:
- Changelog for Opera 7.54u1 for Linux (Opera Software)
- Changelog for Opera 7.54u2 for Linux (Opera Software)
- Changelog for Opera 8.01 for Windows (Opera Software)
- Opera Window Injection Vulnerability (Secunia)