‫ Opera Multiple Vulnerabilities

IRCAD2012112283
ID:IRCAD2012112283
Release Date: 2012-11-06
Criticality level: Highly critical
Software:
Opera 12.x
 
Description:
Multiple vulnerabilities have been reported in Opera, where some have unknown impacts and other can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system.
1)    An unspecified error when handling CORS (Cross-Origin Resource Sharing) requests can be exploited to bypass the same origin policy and e.g. disclose sensitive information from another domain.
2)    An error when handling Data URIs can be exploited to conduct cross-site scripting attacks.
3)    An unspecified error exists. No further information if currently available.
4)    An error when handling SVG images can be exploited to execute arbitrary code.
5)    Another unspecified error exists. No further information if currently available.
The vulnerabilities are reported in versions prior to 12.10.
 
Solution:
Update to version 12.10.
 
References:
 
Secunia:
 

نظرات

بدون نظر
شما برای نظر دادن باید وارد شوید

نوشته

 
تاریخ ایجاد: 17 آبان 1391

امتیاز

امتیاز شما
تعداد امتیازها:0