PT-2005-3319 · Opera · Opera
Publicado
2005-07-28
·
Atualizado
2022-02-28
·
CVE-2005-2405
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Opera version 8.01
Description
The issue arises when the "Arial Unicode MS" font is installed, and Opera does not properly handle extended ASCII characters in the file download dialog box. This allows remote attackers to spoof file extensions, which could trick users into executing arbitrary code.
Recommendations
For Opera version 8.01, consider removing or disabling the "Arial Unicode MS" font to mitigate the risk of file extension spoofing.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opera