Vulnerabilities > CVE-2011-0450 - Remote Security vulnerability in Opera Web Browser

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
opera
microsoft
nessus

Summary

The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers to execute arbitrary code via a crafted web site that hosts an executable file.

Vulnerable Configurations

Part Description Count
Application
Opera
148
OS
Microsoft
1

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_2EDA0C5434AB11E0810300215C6A37BB.NASL
    descriptionOpera reports : Opera 11.01 is a recommended upgrade offering security and stability enhancements. The following security vulnerabilities have been fixed : - Removed support for
    last seen2020-06-01
    modified2020-06-02
    plugin id51928
    published2011-02-10
    reporterThis script is Copyright (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/51928
    titleFreeBSD : opera -- multiple vulnerabilities (2eda0c54-34ab-11e0-8103-00215c6a37bb)
    code
    #%NASL_MIN_LEVEL 80502
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and package checks in this plugin were  
    # extracted from the FreeBSD VuXML database :
    #
    # Copyright 2003-2018 Jacques Vidrine and contributors
    #
    # Redistribution and use in source (VuXML) and 'compiled' forms (SGML,
    # HTML, PDF, PostScript, RTF and so forth) with or without modification,
    # are permitted provided that the following conditions are met:
    # 1. Redistributions of source code (VuXML) must retain the above
    #    copyright notice, this list of conditions and the following
    #    disclaimer as the first lines of this file unmodified.
    # 2. Redistributions in compiled form (transformed to other DTDs,
    #    published online in any format, converted to PDF, PostScript,
    #    RTF and other formats) must reproduce the above copyright
    #    notice, this list of conditions and the following disclaimer
    #    in the documentation and/or other materials provided with the
    #    distribution.
    # 
    # THIS DOCUMENTATION IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS "AS IS"
    # AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
    # THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
    # PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS
    # BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY,
    # OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT
    # OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
    # BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
    # WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
    # OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS DOCUMENTATION,
    # EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(51928);
      script_version("1.8");
      script_cvs_date("Date: 2019/08/02 13:32:40");
    
      script_cve_id("CVE-2011-0450", "CVE-2011-0681", "CVE-2011-0682", "CVE-2011-0683", "CVE-2011-0684", "CVE-2011-0685", "CVE-2011-0686", "CVE-2011-0687");
      script_xref(name:"Secunia", value:"43023");
    
      script_name(english:"FreeBSD : opera -- multiple vulnerabilities (2eda0c54-34ab-11e0-8103-00215c6a37bb)");
      script_summary(english:"Checks for updated packages in pkg_info output");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:
    "The remote FreeBSD host is missing one or more security-related
    updates."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "Opera reports :
    
    Opera 11.01 is a recommended upgrade offering security and stability
    enhancements.
    
    The following security vulnerabilities have been fixed :
    
    - Removed support for 'javascript:' URLs in CSS -o-link values, to
    make it easier for sites to filter untrusted CSS.
    
    - Fixed an issue where large form inputs could allow execution of
    arbitrary code, as reported by Jordi Chancel; see our advisory.
    
    - Fixed an issue which made it possible to carry out clickjacking
    attacks against internal opera: URLs; see our advisory.
    
    - Fixed issues which allowed web pages to gain limited access to files
    on the user's computer; see our advisory.
    
    - Fixed an issue where email passwords were not immediately deleted
    when deleting private data; see our advisory."
      );
      # http://www.opera.com/support/kb/view/982/
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?dca12c44"
      );
      # http://www.opera.com/support/kb/view/983/
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?1c467602"
      );
      # http://www.opera.com/support/kb/view/984/
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?9ca9b915"
      );
      # https://vuxml.freebsd.org/freebsd/2eda0c54-34ab-11e0-8103-00215c6a37bb.html
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?a198f326"
      );
      script_set_attribute(attribute:"solution", value:"Update the affected packages.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:freebsd:freebsd:linux-opera");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:freebsd:freebsd:opera");
      script_set_attribute(attribute:"cpe", value:"p-cpe:/a:freebsd:freebsd:opera-devel");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:freebsd:freebsd");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2011/01/26");
      script_set_attribute(attribute:"patch_publication_date", value:"2011/02/10");
      script_set_attribute(attribute:"plugin_publication_date", value:"2011/02/10");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
      script_family(english:"FreeBSD Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/FreeBSD/release", "Host/FreeBSD/pkg_info");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("freebsd_package.inc");
    
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    if (!get_kb_item("Host/FreeBSD/release")) audit(AUDIT_OS_NOT, "FreeBSD");
    if (!get_kb_item("Host/FreeBSD/pkg_info")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    
    flag = 0;
    
    if (pkg_test(save_report:TRUE, pkg:"opera<11.01")) flag++;
    if (pkg_test(save_report:TRUE, pkg:"opera-devel<11.01")) flag++;
    if (pkg_test(save_report:TRUE, pkg:"linux-opera<11.01")) flag++;
    
    if (flag)
    {
      if (report_verbosity > 0) security_hole(port:0, extra:pkg_report_get());
      else security_hole(0);
      exit(0);
    }
    else audit(AUDIT_HOST_NOT, "affected");
    
  • NASL familyWindows
    NASL idOPERA_1101.NASL
    descriptionThe version of Opera installed on the remote Windows host is earlier than 11.01. Such versions are potentially affected by the following issues : - The Cascading Style Sheets (CSS) Extensions for XML implementation recognizes links to javascript: URLs in the -o-link property, which could be abused to bypass CSS filtering. (CVE-2011-0681) - An integer truncation error exists such that the application may crash when accessing web pages that contain forms having large numbers of items in an
    last seen2020-06-01
    modified2020-06-02
    plugin id51774
    published2011-01-27
    reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/51774
    titleOpera < 11.01 Multiple Vulnerabilities
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(51774);
      script_version("1.12");
      script_cvs_date("Date: 2018/11/15 20:50:27");
    
      script_cve_id(
        "CVE-2011-0450",
        "CVE-2011-0681",
        "CVE-2011-0682",
        "CVE-2011-0683",
        "CVE-2011-0684",
        "CVE-2011-0685",
        "CVE-2011-0686",
        "CVE-2011-0687"
      );
      script_bugtraq_id(45951, 46003, 46036);
      script_xref(name:"EDB-ID", value:"16042");
      script_xref(name:"Secunia", value:"43023");
    
      script_name(english:"Opera < 11.01 Multiple Vulnerabilities");
      script_summary(english:"Checks version number of Opera");
    
      script_set_attribute(attribute:"synopsis", value:
    "The remote host contains a web browser that is affected by multiple
    vulnerabilities");
      script_set_attribute(attribute:"description", value:
    "The version of Opera installed on the remote Windows host is earlier
    than 11.01.  Such versions are potentially affected by the following
    issues :
    
      - The Cascading Style Sheets (CSS) Extensions for XML 
        implementation recognizes links to javascript: URLs in 
        the -o-link property, which could be abused to bypass
        CSS filtering. (CVE-2011-0681)
    
      - An integer truncation error exists such that the 
        application may crash when accessing web pages that
        contain forms having large numbers of items in an  
        'option' element. Such crashes may lead to memory 
        corruption and allow code execution. (982)
    
      - An error exists in the handling of internal 'opera:' 
        URLS that can allow anti-clickjacking configuration
        options to be modified. (983)
    
      - An error exists in the processing of certain HTTP
        requests and responses that can allow limited,
        unauthorized access to local files. (984)
    
      - An error exists in the downloads manager that allows
        unintended executables to be used when attempting to 
        open the folder containing a downloaded file. (985)
    
      - An error exists in the private data deletion process
        that causes the removal of email passwords to be
        delayed. (986)"
      );
      script_set_attribute(attribute:"see_also", value:"http://www.opera.com/support/kb/view/982/");
      script_set_attribute(attribute:"see_also", value:"http://www.opera.com/support/kb/view/983/");
      script_set_attribute(attribute:"see_also", value:"http://www.opera.com/support/kb/view/984/");
      script_set_attribute(attribute:"see_also", value:"http://web.archive.org/web/20130223102306/http://www.opera.com/support/kb/view/985/");
      script_set_attribute(attribute:"see_also", value:"http://web.archive.org/web/20130223102303/http://www.opera.com/support/kb/view/986/");
      script_set_attribute(attribute:"see_also", value:"http://web.archive.org/web/20170713150716/http://www.opera.com:80/docs/changelogs/windows/1101/");
      script_set_attribute(attribute:"solution", value:"Upgrade to Opera 11.01 or later.");
      script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C");
      script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
      script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
      script_set_attribute(attribute:"exploit_available", value:"false");
    
      script_set_attribute(attribute:"vuln_publication_date", value:"2011/01/27");
      script_set_attribute(attribute:"patch_publication_date", value:"2010/01/27");
      script_set_attribute(attribute:"plugin_publication_date", value:"2011/01/27");
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/a:opera:opera_browser");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_family(english:"Windows");
    
      script_copyright(english:"This script is Copyright (C) 2011-2018 Tenable Network Security, Inc.");
    
      script_dependencies("opera_installed.nasl");
      script_require_keys("SMB/Opera/Version");
    
      exit(0);
    }
    
    include("global_settings.inc");
    include("misc_func.inc");
    
    version = get_kb_item_or_exit("SMB/Opera/Version");
    
    version_ui = get_kb_item("SMB/Opera/Version_UI");
    if (isnull(version_ui)) version_report = version;
    else version_report = version_ui;
    
    if (ver_compare(ver:version, fix:'11.1.1190.0') == -1)
    {
      if (report_verbosity > 0)
      {
        install_path = get_kb_item("SMB/Opera/Path");
    
        report = 
          '\n  Path              : ' + install_path +
          '\n  Installed version : ' + version_report +
          '\n  Fixed version     : 11.01\n';
        security_hole(port:get_kb_item("SMB/transport"), extra:report);
      }
      else security_hole(port:get_kb_item("SMB/transport"));
      exit(0);
    }
    else exit(0, "The host is not affected since Opera "+version_report+" is installed.");
    

Oval

accepted2013-12-23T04:00:10.450-05:00
classvulnerability
contributors
  • nameSecPod Team
    organizationSecPod Technologies
  • nameJosh Turpin
    organizationSymantec Corporation
  • nameMaria Kedovskaya
    organizationALTX-SOFT
definition_extensions
commentOpera Browser is installed
ovaloval:org.mitre.oval:def:6482
descriptionThe downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers to execute arbitrary code via a crafted web site that hosts an executable file.
familywindows
idoval:org.mitre.oval:def:12369
statusaccepted
submitted2011-03-22T15:16:26
titleSecurity vulnerability in download manager in Opera before 11.01
version12