Vulnerabilities > CVE-2008-4292 - Unspecified vulnerability in Opera Browser
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN opera
nessus
Summary
Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown impact and attack vectors. NOTE: it is not clear whether this is a vulnerability, but the vendor included it in a security section of the advisory.
Vulnerable Configurations
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200811-01.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200811-01 (Opera: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in Opera: Opera does not restrict the ability of a framed web page to change the address associated with a different frame (CVE-2008-4195). Chris Weber (Casaba Security) discovered a Cross-site scripting vulnerability (CVE-2008-4196). Michael A. Puls II discovered that Opera can produce argument strings that contain uninitialized memory, when processing custom shortcut and menu commands (CVE-2008-4197). Lars Kleinschmidt discovered that Opera, when rendering an HTTP page that has loaded an HTTPS page into a frame, displays a padlock icon and offers a security information dialog reporting a secure connection (CVE-2008-4198). Opera does not prevent use of links from web pages to feed source files on the local disk (CVE-2008-4199). Opera does not ensure that the address field of a news feed represents the feed |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 34689 |
published | 2008-11-04 |
reporter | This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/34689 |
title | GLSA-200811-01 : Opera: Multiple vulnerabilities |
code |
|
References
- http://bugs.gentoo.org/show_bug.cgi?id=235298
- http://bugs.gentoo.org/show_bug.cgi?id=235298
- http://my.opera.com/community/forums/topic.dml?id=241988&t=1222404671&page=1
- http://my.opera.com/community/forums/topic.dml?id=241988&t=1222404671&page=1
- http://my.opera.com/yngve/blog/2008/06/27/nobody-checks-the-padlock-debunked-by-opera-users
- http://my.opera.com/yngve/blog/2008/06/27/nobody-checks-the-padlock-debunked-by-opera-users
- http://secunia.com/advisories/31549
- http://secunia.com/advisories/31549
- http://secunia.com/advisories/32538
- http://secunia.com/advisories/32538
- http://security.gentoo.org/glsa/glsa-200811-01.xml
- http://security.gentoo.org/glsa/glsa-200811-01.xml
- http://www.openwall.com/lists/oss-security/2008/09/19/2
- http://www.openwall.com/lists/oss-security/2008/09/19/2
- http://www.openwall.com/lists/oss-security/2008/09/24/4
- http://www.openwall.com/lists/oss-security/2008/09/24/4
- http://www.opera.com/docs/changelogs/freebsd/952/
- http://www.opera.com/docs/changelogs/freebsd/952/
- http://www.opera.com/docs/changelogs/linux/952/
- http://www.opera.com/docs/changelogs/linux/952/
- http://www.opera.com/docs/changelogs/mac/952/
- http://www.opera.com/docs/changelogs/mac/952/
- http://www.opera.com/docs/changelogs/solaris/952/
- http://www.opera.com/docs/changelogs/solaris/952/
- http://www.opera.com/docs/changelogs/windows/952/
- http://www.opera.com/docs/changelogs/windows/952/
- http://www.vupen.com/english/advisories/2008/2416
- http://www.vupen.com/english/advisories/2008/2416
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45589
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45589