Opera Web Browser Secure Cookie Security Bypass Vulnerability
BID:49134
Info
Opera Web Browser Secure Cookie Security Bypass Vulnerability
| Bugtraq ID: | 49134 |
| Class: | Design Error |
| CVE: |
CVE-2008-7297 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2008 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Chris Evans |
| Vulnerable: |
Opera Software Opera Web Browser 9.64 Opera Software Opera Web Browser 9.63 Opera Software Opera Web Browser 9.62 Opera Software Opera Web Browser 9.61 Opera Software Opera Web Browser 9.60 Opera Software Opera Web Browser 9.52 Opera Software Opera Web Browser 9.51 Opera Software Opera Web Browser 9.5 Opera Software Opera Web Browser 9.27 Opera Software Opera Web Browser 9.26 Opera Software Opera Web Browser 9.25 Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 Opera Software Opera Web Browser 11.00 Opera Software Opera Web Browser 10.63 Opera Software Opera Web Browser 10.62 Opera Software Opera Web Browser 10.61 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.53 Opera Software Opera Web Browser 10.52 Opera Software Opera Web Browser 10.51 Opera Software Opera Web Browser 10.50 Opera Software Opera Web Browser 10.10 Opera Software Opera Web Browser 10.1 Opera Software Opera Web Browser 10.01 Opera Software Opera Web Browser 10.00 |
| Not Vulnerable: | |
Discussion
Opera Web Browser Secure Cookie Security Bypass Vulnerability
The Opera Web browser is prone to a security-bypass vulnerability that affects secure cookies (cookies that are set and exchanged only over an HTTPS communication).
Attackers can exploit this issue to overwrite or delete arbitrary cookies by sending a specially crafted HTTP response through a man-in-the-middle attack. This allows attackers to bypass security features provided by secure cookies.
The Opera Web browser is prone to a security-bypass vulnerability that affects secure cookies (cookies that are set and exchanged only over an HTTPS communication).
Attackers can exploit this issue to overwrite or delete arbitrary cookies by sending a specially crafted HTTP response through a man-in-the-middle attack. This allows attackers to bypass security features provided by secure cookies.
Exploit / POC
Opera Web Browser Secure Cookie Security Bypass Vulnerability
Attackers can exploit this issue through man-in-the-middle attacks.
Attackers can exploit this issue through man-in-the-middle attacks.
Solution / Fix
Opera Web Browser Secure Cookie Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Opera Web Browser Secure Cookie Security Bypass Vulnerability
References:
References:
- Browser Security Handbook (browsersec)
- Cookie forcing (Chris Evans)
- Cookie Forcing - Trust your cookies no more (Michael Coates)
- fyi: Strict Transport Security specification (JeffH)
- Opera Home Page (Opera Software)
- Some less obvious benefits of HSTS (Chris Evans)