Summary
The host is installed with Opera web browser and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let attackers to cause a denial of service or execute arbitrary code.
Impact Level: Application
Solution
Upgrade to Opera 10.54 or later,
For updates refer to http://www.opera.com/download/?os=windows&list=all
Insight
The multiple flaws are cause due to:
- Fails to restrict certain uses of homograph characters in domain names, which makes it easier for remote attackers to spoof IDN domains.
- Fails to properly restrict access to the full pathname of a file selected for upload, which allows attackers to obtain potentially sensitive information.
- Cross site scripting (XSS) vulnerability when handling a data: URI.
- Fails to properly enforce permission requirements for widget filesystem.
Affected
Opera version prior to 10.54 on Windows.
References
Severity
Classification
-
CVE CVE-2010-2660, CVE-2010-2661, CVE-2010-2665, CVE-2010-2666 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities