FreeBSD : opera -- redirection XSS vulnerability (985bfcf0-e1d7-11d9-b875-0001020eed82)

high Nessus Plugin ID 19043

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

A Secunia Advisory reports :

Secunia Research has discovered a vulnerability in Opera, which can be exploited by malicious people to conduct cross-site scripting attacks against users.

The vulnerability is caused due to input not being sanitised, when Opera generates a temporary page for displaying a redirection when 'Automatic redirection' is disabled (not default setting).

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?8d381381

https://blogs.opera.com/desktop/#security

http://www.nessus.org/u?5b15a527

Plugin Details

Severity: High

ID: 19043

File Name: freebsd_pkg_985bfcf0e1d711d9b8750001020eed82.nasl

Version: 1.19

Type: local

Published: 7/13/2005

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:linux-opera, p-cpe:/a:freebsd:freebsd:opera, p-cpe:/a:freebsd:freebsd:opera-devel, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 6/20/2005

Vulnerability Publication Date: 6/16/2005

Reference Information

Secunia: 15423