PT-2008-6322 · Opera · Opera
Send9
·
Publicado
2008-11-20
·
Atualizado
2017-10-19
·
CVE-2008-5178
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Opera version 9.62
Description
The issue is caused by a boundary error in the processing of 'file://' URIs, which can lead to a heap-based buffer overflow when an overly long "file://" URI is processed. This can be exploited by malicious people to compromise a user's system, potentially allowing execution of arbitrary code if the user is tricked into opening a malicious HTML file.
Recommendations
For Opera version 9.62, consider avoiding the use of overly long "file://" URIs until a fix is available. As a temporary workaround, restrict access to potentially malicious HTML files to minimize the risk of exploitation.
Exploit
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opera