Opera Web Browser Prior to 12.10 SSL Certificate Validation Security Weakness
BID:57121
Info
Opera Web Browser Prior to 12.10 SSL Certificate Validation Security Weakness
| Bugtraq ID: | 57121 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-6461 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2012 12:00AM |
| Updated: | Mar 19 2015 09:09AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Opera Software Opera Web Browser 12 Opera Software Opera Web Browser 11.64 Opera Software Opera Web Browser 11.62 Opera Software Opera Web Browser 11.61 Opera Software Opera Web Browser 11.60 Opera Software Opera Web Browser 11.52 Opera Software Opera Web Browser 11.51 Opera Software Opera Web Browser 11.50 Opera Software Opera Web Browser 11.11 Opera Software Opera Web Browser 11.10 Opera Software Opera Web Browser 11.01 Opera Software Opera Web Browser 11.00 Opera Software Opera Web Browser 10.63 Opera Software Opera Web Browser 10.62 Opera Software Opera Web Browser 10.61 Opera Software Opera Web Browser 10.60 Opera Software Opera Web Browser 10.54 Opera Software Opera Web Browser 10.53 Opera Software Opera Web Browser 10.52 Opera Software Opera Web Browser 10.51 Opera Software Opera Web Browser 10.50 Opera Software Opera Web Browser 10.10 Opera Software Opera Web Browser 10.1 Opera Software Opera Web Browser 10.01 Opera Software Opera Web Browser 10.00 Opera Software Opera Web Browser 10 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Opera Web Browser Prior to 12.10 SSL Certificate Validation Security Weakness
Opera Web Browser is prone to a security weakness in validating SSL certificates.
Successfully exploiting this issue results in users having a false sense of security which may aid attackers in phishing-style attacks by bypassing security warnings when invalid certificates are used in SSL HTTP connections.
Opera Web Browser versions prior to 12.10 are affected.
Opera Web Browser is prone to a security weakness in validating SSL certificates.
Successfully exploiting this issue results in users having a false sense of security which may aid attackers in phishing-style attacks by bypassing security warnings when invalid certificates are used in SSL HTTP connections.
Opera Web Browser versions prior to 12.10 are affected.
Exploit / POC
Opera Web Browser Prior to 12.10 SSL Certificate Validation Security Weakness
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Opera Web Browser Prior to 12.10 SSL Certificate Validation Security Weakness
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.