Opera Web Browser prior to 10.01 Multiple Security Vulnerabilities
BID:36850
Info
Opera Web Browser prior to 10.01 Multiple Security Vulnerabilities
| Bugtraq ID: | 36850 |
| Class: | Unknown |
| CVE: |
CVE-2009-3266 CVE-2009-3831 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2009 12:00AM |
| Updated: | Nov 25 2009 07:35PM |
| Credit: | Chris Weber of Casaba Security, Inferno, and John Daggett |
| Vulnerable: |
S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Opera Software Opera Web Browser 9.64 Opera Software Opera Web Browser 9.63 Opera Software Opera Web Browser 9.62 Opera Software Opera Web Browser 9.61 Opera Software Opera Web Browser 9.60 Opera Software Opera Web Browser 9.52 Opera Software Opera Web Browser 9.51 Opera Software Opera Web Browser 9.5 Opera Software Opera Web Browser 9.27 Opera Software Opera Web Browser 9.26 Opera Software Opera Web Browser 9.25 Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 Opera Software Opera Web Browser 10 |
| Not Vulnerable: |
Opera Software Opera Web Browser 10.1 |
Discussion
Opera Web Browser prior to 10.01 Multiple Security Vulnerabilities
Opera Web Browser is prone to multiple security vulnerabilities.
Successful exploits may allow attackers to execute arbitrary code, bypass certain security restrictions, or perform spoofing attacks.
Versions prior to Opera 10.01 are vulnerable.
Opera Web Browser is prone to multiple security vulnerabilities.
Successful exploits may allow attackers to execute arbitrary code, bypass certain security restrictions, or perform spoofing attacks.
Versions prior to Opera 10.01 are vulnerable.
Exploit / POC
Opera Web Browser prior to 10.01 Multiple Security Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Note that some of the issues may not require any exploit code and may be trivial to exploit via standard tools.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Note that some of the issues may not require any exploit code and may be trivial to exploit via standard tools.
Solution / Fix
Opera Web Browser prior to 10.01 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Opera Web Browser prior to 10.01 Multiple Security Vulnerabilities
References:
References:
- Hijacking Opera�??s Native Page using malicious RSS payloads (SecureThoughts)
- Opera Homepage (Opera Software)
- Hijacking Opera's Native Page using malicious RSS payloads ("Inferno"
) - Advisory: Certain domain names can allow execution of arbitrary code (Opera)
- Advisory: Opera may allow scripts to access feeds (Opera)
- Advisory: Web fonts can be used to spoof the page address (Opera)