PT-2008-6322 · Opera · Opera
Send9
·
Published
2008-11-20
·
Updated
2017-10-19
·
CVE-2008-5178
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Opera version 9.62
Description
The issue is caused by a boundary error in the processing of 'file://' URIs, which can lead to a heap-based buffer overflow when an overly long "file://" URI is processed. This can be exploited by malicious people to compromise a user's system, potentially allowing execution of arbitrary code if the user is tricked into opening a malicious HTML file.
Recommendations
For Opera version 9.62, consider avoiding the use of overly long "file://" URIs until a fix is available. As a temporary workaround, restrict access to potentially malicious HTML files to minimize the risk of exploitation.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opera