Summary
The host is installed with Opera web browser and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let attackers to cause a denial of service or execute arbitrary code.
Impact Level: Application
Solution
Upgrade to Opera 10.60 or later,
For updates refer to http://www.opera.com/download/?os=windows&list=all
Insight
The multiple flaws are cause due to:
- Browser does not properly prevent certain double-click operations from running a program located on a web site.
- Browser does not properly restrict certain interaction between plug-ins, file inputs, and the clipboard, which allows attackers to trigger the uploading of arbitrary files via a crafted web site.
- Error in the handling of popup blocker via a 'javascript:' URL and a 'ake click'.
- Error in the handling of an ended event handler that changes the SRC attribute of an AUDIO element.
- Error in the handling of certain HTML content that has an unclosed 'SPAN' element with absolute positioning.
Affected
Opera version prior to 10.60 and prior on Windows.
References
Severity
Classification
-
CVE CVE-2010-2657, CVE-2010-2658, CVE-2010-2662, CVE-2010-2663, CVE-2010-2664 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities