OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

opera -- multiple vulnerabilities

Affected packages
opera < 7.54u1

Details

VuXML ID 9fc8eb84-5209-11d9-98b6-00065bd5b0b6
Discovery 2004-12-08
Entry 2004-12-18

Secunia reports:

Secunia Research has discovered a vulnerability in Opera, which can be exploited by malicious people to trick users into executing malicious files. The vulnerability is caused due to the filename and the "Content-Type" header not being sufficiently validated before being displayed in the file download dialog. This can be exploited to spoof file types in the download dialog by passing specially crafted "Content-Disposition" and "Content-Type" headers containing dots and ASCII character code 160.

Secunia Research has reported a vulnerability in Opera, which can be exploited by malicious people to spoof the content of websites. The problem is that a website can inject content into another site's window if the target name of the window is known. This can e.g. be exploited by a malicious website to spoof the content of a pop-up window opened on a trusted website.

References

URL http://secunia.com/advisories/12981/
URL http://secunia.com/advisories/13253/
URL http://www.opera.com/linux/changelogs/754u1/