PT-2004-2979 · Opera · Opera Web Browser+1
Published
2004-02-11
·
Updated
2022-02-28
·
CVE-2004-2083
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Opera Web Browser versions 7.0 through 7.23
Description
The issue allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, making the malicious file appear as a trusted file type. This can occur when a malicious website provides a file for download with a crafted filename, potentially leading to arbitrary code execution and a loss of confidentiality, integrity, and/or availability.
Recommendations
For Opera Web Browser versions 7.0 through 7.23, consider disabling the file download feature or restricting the execution of files with embedded CLSID until a patch is available. As a temporary workaround, users should be cautious when downloading files from untrusted sources and avoid executing files without verifying their authenticity.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opera
Opera Web Browser