Opera Relative Path Directory Traversal File Corruption Vulnerability
BID:9279
Info
Opera Relative Path Directory Traversal File Corruption Vulnerability
| Bugtraq ID: | 9279 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2003 12:00AM |
| Updated: | Dec 23 2003 12:00AM |
| Credit: | Discovery is credited to :: Operash ::. |
| Vulnerable: |
Opera Software Opera Web Browser 7.22 Opera Software Opera Web Browser 7.21 Opera Software Opera Web Browser 7.20 Beta 1 build 2981 Opera Software Opera Web Browser 7.20 Opera Software Opera Web Browser 7.11 j Opera Software Opera Web Browser 7.11 b Opera Software Opera Web Browser 7.11 Opera Software Opera Web Browser 7.10 Opera Software Opera Web Browser 7.0 win32 Beta 2 Opera Software Opera Web Browser 7.0 win32 Beta 1 Opera Software Opera Web Browser 7.0 win32 Opera Software Opera Web Browser 7.0 3win32 Opera Software Opera Web Browser 7.0 2win32 Opera Software Opera Web Browser 7.0 1win32 |
| Not Vulnerable: |
Opera Software Opera Web Browser 7.23 |
Discussion
Opera Relative Path Directory Traversal File Corruption Vulnerability
Opera is prone to a file corruption vulnerability. This issue is exposed when a user is presented with a file dialog, which will cause the creation of a temporary file. It is possible to specify a relative path to another file on the system using directory traversal sequences when the download dialog is displayed. If the client user has write permissions to the attacker-specified file, it will be corrupted.
This could be exploited to delete sensitive files on the systems. It is not currently known if this could be used to trojan files on the system.
This issue was reported in Opera for Windows platforms. It is not known whether other platforms are also affected.
Opera is prone to a file corruption vulnerability. This issue is exposed when a user is presented with a file dialog, which will cause the creation of a temporary file. It is possible to specify a relative path to another file on the system using directory traversal sequences when the download dialog is displayed. If the client user has write permissions to the attacker-specified file, it will be corrupted.
This could be exploited to delete sensitive files on the systems. It is not currently known if this could be used to trojan files on the system.
This issue was reported in Opera for Windows platforms. It is not known whether other platforms are also affected.
Exploit / POC
Opera Relative Path Directory Traversal File Corruption Vulnerability
The following proof of concept exploit has been supplied:
The following proof of concept exploit has been supplied:
Solution / Fix
Opera Relative Path Directory Traversal File Corruption Vulnerability
Solution:
This issue has been addressed in Opera 7.23. Users are advised to upgrade.
Opera Software Opera Web Browser 7.20
Opera Software Opera Web Browser 7.21
Opera Software Opera Web Browser 7.22
Solution:
This issue has been addressed in Opera 7.23. Users are advised to upgrade.
Opera Software Opera Web Browser 7.20
-
Opera Software Opera 7.23 for Windows
http://www.opera.com/download/
Opera Software Opera Web Browser 7.21
-
Opera Software Opera 7.23 for Windows
http://www.opera.com/download/
Opera Software Opera Web Browser 7.22
-
Opera Software Opera 7.23 for Windows
http://www.opera.com/download/
References
Opera Relative Path Directory Traversal File Corruption Vulnerability
References:
References:
- Opera Web Browser Home Page (Opera Software)
- [Opera 7] Arbitrary File Auto-Saved Vulnerability. (:: Operash ::
) - [Opera 7] Arbitrary File Delete Vulnerability (":: Operash ::"
)