Opera Web Browser IFRAME Loading Information Disclosure Vulnerability
BID:51066
Info
Opera Web Browser IFRAME Loading Information Disclosure Vulnerability
| Bugtraq ID: | 51066 |
| Class: | Access Validation Error |
| CVE: |
CVE-2011-4690 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2011 12:00AM |
| Updated: | Dec 14 2011 12:00AM |
| Credit: | Edward W. Felten and Michael A. Schneider |
| Vulnerable: |
Opera Software Opera Web Browser 9.64 Opera Software Opera Web Browser 9.63 Opera Software Opera Web Browser 9.62 Opera Software Opera Web Browser 9.61 Opera Software Opera Web Browser 9.60 beta 1 Opera Software Opera Web Browser 9.60 Opera Software Opera Web Browser 9.52 Opera Software Opera Web Browser 9.51 Opera Software Opera Web Browser 9.50 beta Opera Software Opera Web Browser 9.5 Opera Software Opera Web Browser 9.27 Opera Software Opera Web Browser 9.26 Opera Software Opera Web Browser 9.25 Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 beta 1 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 Opera Software Opera Web Browser 11.60 Opera Software Opera Web Browser 11.52 Opera Software Opera Web Browser 11.51 Opera Software Opera Web Browser 11.50 Opera Software Opera Web Browser 11.11 Opera Software Opera Web Browser 11.10 Opera Software Opera Web Browser 11.01 Opera Software Opera Web Browser 11.00 Opera Software Opera Web Browser 10.63 Opera Software Opera Web Browser 10.62 Opera Software Opera Web Browser 10.62 Opera Software Opera Web Browser 10.61 Opera Software Opera Web Browser 10.60 Beta1 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.53 B Opera Software Opera Web Browser 10.53 Opera Software Opera Web Browser 10.52 Opera Software Opera Web Browser 10.51 Opera Software Opera Web Browser 10.50 Beta2 Opera Software Opera Web Browser 10.50 Beta1 Opera Software Opera Web Browser 10.50 Opera Software Opera Web Browser 10.10 Beta1 Opera Software Opera Web Browser 10.10 Opera Software Opera Web Browser 10.1 Opera Software Opera Web Browser 10.01 Opera Software Opera Web Browser 10.00 Beta3 Opera Software Opera Web Browser 10.00 Beta2 Opera Software Opera Web Browser 10.00 Beta1 Opera Software Opera Web Browser 10.00 Opera Software Opera Web Browser 10 |
| Not Vulnerable: | |
Discussion
Opera Web Browser IFRAME Loading Information Disclosure Vulnerability
The Opera Web Browser is prone to an information-disclosure vulnerability.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content.
Successful exploits will allow attackers to enumerate documents in the browser cache. Information obtained may aid in further attacks.
Opera 11.60 and prior versions are vulnerable.
The Opera Web Browser is prone to an information-disclosure vulnerability.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a page containing malicious content.
Successful exploits will allow attackers to enumerate documents in the browser cache. Information obtained may aid in further attacks.
Opera 11.60 and prior versions are vulnerable.
Exploit / POC
Opera Web Browser IFRAME Loading Information Disclosure Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted site.
An attacker can exploit this issue by enticing an unsuspecting user to visit a crafted site.
Solution / Fix
Opera Web Browser IFRAME Loading Information Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Opera Web Browser IFRAME Loading Information Disclosure Vulnerability
References:
References:
- Opera Homepage (Opera Software)
- Rapid history extraction through non-destructive cache timing (v8) (Michal Zalewski)
- Timing Attacks on Web Privacy Timing Attacks on Web Privacy (Edward W. Felten and Michael A. Schneider)