PT-2004-2979 · Opera · Opera Web Browser+1
Publicado
2004-02-11
·
Atualizado
2022-02-28
·
CVE-2004-2083
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Opera Web Browser versions 7.0 through 7.23
Description
The issue allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, making the malicious file appear as a trusted file type. This can occur when a malicious website provides a file for download with a crafted filename, potentially leading to arbitrary code execution and a loss of confidentiality, integrity, and/or availability.
Recommendations
For Opera Web Browser versions 7.0 through 7.23, consider disabling the file download feature or restricting the execution of files with embedded CLSID until a patch is available. As a temporary workaround, users should be cautious when downloading files from untrusted sources and avoid executing files without verifying their authenticity.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Opera
Opera Web Browser