Opera Web Browser Prior to 10.63 Multiple Security Vulnerabilities
BID:43920
Info
Opera Web Browser Prior to 10.63 Multiple Security Vulnerabilities
| Bugtraq ID: | 43920 |
| Class: | Design Error |
| CVE: |
CVE-2010-4046 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2010 12:00AM |
| Updated: | Apr 26 2011 05:23PM |
| Credit: | Isaac Dawson, Nirankush Panchbhai, and Opera. |
| Vulnerable: |
Opera Software Opera Web Browser 10.62 Opera Software Opera Web Browser 10.61 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.53 B Opera Software Opera Web Browser 10.53 Opera Software Opera Web Browser 10.52 Opera Software Opera Web Browser 10.51 Opera Software Opera Web Browser 10.50 Beta2 Opera Software Opera Web Browser 10.50 Beta1 Opera Software Opera Web Browser 10.50 Opera Software Opera Web Browser 10.10 Beta1 Opera Software Opera Web Browser 10.10 Opera Software Opera Web Browser 10.1 Opera Software Opera Web Browser 10.01 Opera Software Opera Web Browser 10.00 Beta3 Opera Software Opera Web Browser 10.00 Beta2 Opera Software Opera Web Browser 10.00 Beta1 Opera Software Opera Web Browser 10.00 Opera Software Opera Web Browser 10 |
| Not Vulnerable: |
Opera Software Opera Web Browser 10.63 |
Discussion
Opera Web Browser Prior to 10.63 Multiple Security Vulnerabilities
The Opera web browser is prone to a cross-domain scripting vulnerability, an address bar URI-spoofing vulnerability, a cross-site-scripting vulnerability and an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to bypass certain security protections, execute arbitrary code, display arbitrary content with a spoofed URI and perform phishing attacks, bypass the same-origin protection and obtain potentially sensitive information, steal sensitive video information, and steal cookie-based authentication credentials and other sensitive data that may aid in further attacks. Other attacks are also possible.
Opera versions prior to 10.63 are vulnerable.
The Opera web browser is prone to a cross-domain scripting vulnerability, an address bar URI-spoofing vulnerability, a cross-site-scripting vulnerability and an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to bypass certain security protections, execute arbitrary code, display arbitrary content with a spoofed URI and perform phishing attacks, bypass the same-origin protection and obtain potentially sensitive information, steal sensitive video information, and steal cookie-based authentication credentials and other sensitive data that may aid in further attacks. Other attacks are also possible.
Opera versions prior to 10.63 are vulnerable.
Exploit / POC
Opera Web Browser Prior to 10.63 Multiple Security Vulnerabilities
Attackers can exploit some of the issues by enticing a user to visit a malicious site.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Attackers can exploit some of the issues by enticing a user to visit a malicious site.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Opera Web Browser Prior to 10.63 Multiple Security Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Opera Web Browser Prior to 10.63 Multiple Security Vulnerabilities
References:
References:
- Advisory: Cross-domain checks may be bypassed, allowing limited data theft using (Opera)
- Advisory: JavaScript might run in the wrong context if loaded from error page (Opera)
- Advisory: Manipulating the window can be used to spoof the page address (Opera)
- Advisory: Private video streams can be intercepted (Opera)
- Advisory: Reloads and redirects can allow spoofing and cross site scripting (Opera)
- Opera 10.63 for Windows changelog (Opera)
- Opera Homepage (Opera Software)
- MSVR11-002 HTML5 Implementation in Chrome and Opera Could Allow Information Disc (Microsoft)