PT-2008-6322 · Opera · Opera

Send9

·

Publicado

2008-11-20

·

Atualizado

2017-10-19

·

CVE-2008-5178

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Opera version 9.62
Description The issue is caused by a boundary error in the processing of 'file://' URIs, which can lead to a heap-based buffer overflow when an overly long "file://" URI is processed. This can be exploited by malicious people to compromise a user's system, potentially allowing execution of arbitrary code if the user is tricked into opening a malicious HTML file.
Recommendations For Opera version 9.62, consider avoiding the use of overly long "file://" URIs until a fix is available. As a temporary workaround, restrict access to potentially malicious HTML files to minimize the risk of exploitation.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-5178

Produtos afetados

Opera