Opera Web Browser Mail Client Multiple Vulnerabilities
BID:14880
Info
Opera Web Browser Mail Client Multiple Vulnerabilities
| Bugtraq ID: | 14880 |
| Class: | Unknown |
| CVE: |
CVE-2005-3006 CVE-2005-3007 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to Jakob Balle, Secunia Research. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. beagle 10.0 Opera Software Opera Web Browser 8.0 2 |
| Not Vulnerable: |
Opera Software Opera Web Browser 8.50 |
Discussion
Opera Web Browser Mail Client Multiple Vulnerabilities
Opera Web Browser Mail client is affected by multiple vulnerabilities. These issues could allow remote attackers to spoof attachment names and carry out script injection attacks.
These vulnerabilities may also be combined to carry out various attacks.
Opera Web Browser 8.02 is reportedly vulnerable, however, it is likely that other versions are affected as well.
Opera Web Browser Mail client is affected by multiple vulnerabilities. These issues could allow remote attackers to spoof attachment names and carry out script injection attacks.
These vulnerabilities may also be combined to carry out various attacks.
Opera Web Browser 8.02 is reportedly vulnerable, however, it is likely that other versions are affected as well.
Exploit / POC
Opera Web Browser Mail Client Multiple Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Opera Web Browser Mail Client Multiple Vulnerabilities
Solution:
Opera 8.50 is available to address these and other issues.
SUSE has released security announcement SUSE-SA:2005:057 addressing this issue. Please see the referenced advisory for further information.
Opera Software Opera Web Browser 8.0 2
Solution:
Opera 8.50 is available to address these and other issues.
SUSE has released security announcement SUSE-SA:2005:057 addressing this issue. Please see the referenced advisory for further information.
Opera Software Opera Web Browser 8.0 2
-
Opera Software Opera 8.50
http://www.opera.com/download/ -
SUSE opera-8.50-1.1.i586.rpm
SUSE Linux 9.1
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/opera-8.50-1.1.i5 86.rpm -
SUSE opera-8.50-2.1.i586.rpm
SUSE Linux 10.0
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/opera-8.50-2.1.i 586.rpm -
SUSE opera-8.50-2.1.i586.rpm
SUSE Linux 9.2
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/opera-8.50-2.1.i5 86.rpm -
SUSE opera-8.50-2.1.i586.rpm
SUSE Linux 9.3
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/opera-8.50-2.1.i5 86.rpm -
SUSE opera-8.50-2.1.x86_64.rpm
SUSE Linux 10.0
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/opera-8.50-2.1 .x86_64.rpm -
SUSE opera-8.50-2.1.x86_64.rpm
SUSE Linux 9.2
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/opera-8.50-2.1. x86_64.rpm -
SUSE opera-8.50-2.1.x86_64.rpm
SUSE Linux 9.3
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/opera-8.50-2.1. x86_64.rpm
References
Opera Web Browser Mail Client Multiple Vulnerabilities
References:
References:
- Opera 8.50 for Windows Changelog (Opera Software)
- Secunia Research: Opera Mail Client Attachment Spoofing and Script Insertion (Secunia Research
)