PT-2005-3319 · Opera · Opera
Published
2005-07-28
·
Updated
2022-02-28
·
CVE-2005-2405
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Opera version 8.01
Description
The issue arises when the "Arial Unicode MS" font is installed, and Opera does not properly handle extended ASCII characters in the file download dialog box. This allows remote attackers to spoof file extensions, which could trick users into executing arbitrary code.
Recommendations
For Opera version 8.01, consider removing or disabling the "Arial Unicode MS" font to mitigate the risk of file extension spoofing.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opera