PT-2010-3614 · Opera · Opera
Published
2010-05-20
·
Updated
2018-10-10
·
CVE-2010-1993
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Opera version 9.52
Description
The issue arises from improper handling of an IFRAME element with a mailto: URL in its SRC attribute. This allows remote attackers to cause a denial of service, specifically resource consumption, by creating an HTML document containing many IFRAME elements.
Recommendations
For Opera version 9.52, consider avoiding the use of IFRAME elements with mailto: URLs in their SRC attribute until a fix is available. As a temporary workaround, restrict the number of IFRAME elements in HTML documents to minimize the risk of resource consumption.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opera