FreeBSD : opera -- multiple vulnerabilities (d6b092bd-61e1-11da-b64c-0001020eed82)

medium Nessus Plugin ID 21517

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Opera reports :

It is possible to make a form input that looks like an image link. If the form input has a 'title' attribute, the status bar will show the 'title'. A 'title' which looks like a URL can mislead the user, since the title can say http://nice.familiar.com/, while the form action can be something else.

Opera's tooltip says 'Title:' before the title text, making a spoof URL less convincing. A user who has enabled the status bar and disabled tooltips can be affected by this. Neither of these settings are Opera's defaults.

This exploit is mostly of interest to users who disable JavaScript. If JavaScript is enabled, any link target or form action can be overridden by the script. The tooltip and the statusbar can only be trusted to show the true location if JavaScript is disabled.

Java code using LiveConnect methods to remove a property of a JavaScript object may in some cases use NULL pointers that can make Opera crash. This crash is not exploitable and such code is rare on the web.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?c857f398

http://www.nessus.org/u?d89d7e73

http://www.nessus.org/u?039e1e2b

Plugin Details

Severity: Medium

ID: 21517

File Name: freebsd_pkg_d6b092bd61e111dab64c0001020eed82.nasl

Version: 1.15

Type: local

Published: 5/13/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.7

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:linux-opera, p-cpe:/a:freebsd:freebsd:opera, p-cpe:/a:freebsd:freebsd:opera-devel, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 11/30/2005

Vulnerability Publication Date: 11/16/2005

Reference Information

CVE: CVE-2005-3699

Secunia: 17571