Vulnerabilities > CVE-2011-4684 - Cryptographic Issues vulnerability in Opera Browser

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
opera
CWE-310
critical
nessus
exploit available

Summary

Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."

Vulnerable Configurations

Part Description Count
Application
Opera
125

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Signature Spoofing by Key Recreation
    An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.

Exploit-Db

descriptionOpera Web Browser Prior to 11.60 Multiple Denial of Service and Unspecified Vulnerabilitiies. CVE-2011-4684. Dos exploit for windows platform
idEDB-ID:36443
last seen2016-02-04
modified2011-12-12
published2011-12-12
reporteranonymous
sourcehttps://www.exploit-db.com/download/36443/
titleOpera Web Browser Prior to 11.60 - Multiple Denial of Service and Unspecified Vulnerabilitiies

Nessus

  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_3_OPERA-111208.NASL
    descriptionopera was updated to version 11.60 to fix several security issues
    last seen2020-06-01
    modified2020-06-02
    plugin id75699
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75699
    titleopenSUSE Security Update : opera (openSUSE-SU-2011:1314-1)
  • NASL familyWindows
    NASL idOPERA_1160.NASL
    descriptionThe version of Opera installed on the remote Windows host is prior to 11.60. It is, therefore, affected by multiple vulnerabilities : - An unspecified error exists that can allow URL spoofing in the address bar. (CVE-2011-4010) - Top level domain separation rules are not honored for two-letter top level domains, e.g.,
    last seen2020-06-01
    modified2020-06-02
    plugin id57039
    published2011-12-07
    reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/57039
    titleOpera < 11.60 Multiple Vulnerabilities (BEAST)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_4_OPERA-111208.NASL
    descriptionopera was updated to version 11.60 to fix several security issues
    last seen2020-06-01
    modified2020-06-02
    plugin id75986
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75986
    titleopenSUSE Security Update : opera (openSUSE-SU-2011:1314-1)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2011-76.NASL
    descriptionOpera version update to 11.60
    last seen2020-06-01
    modified2020-06-02
    plugin id74533
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/74533
    titleopenSUSE Security Update : opera (openSUSE-2011-76)