Opera < 12.01 Multiple Vulnerabilities

This script is Copyright (C) 2012-2015 Tenable Network Security, Inc.


Synopsis :

The remote host contains a web browser that is affected by multiple
issues.

Description :

The version of Opera installed on the remote host is earlier than
12.01 and is, therefore, reportedly affected by multiple issues :

- An error exists in the handling of certain URLs that
can lead to memory corruption and possible code
execution. (1016)

- Errors exist in the handling of DOM elements and
certain HTML characters that can lead to cross-site
scripting. (1025, 1026)

- Download dialog boxes can be made small enough that
users may not realize they are accepting a download
and further, executing such a download. (1027)

- An attacker could cause an application crash by tricking
a user into connecting to a malicious site, as
demonstrated by the Lenovo 'Shop Now' page.
(CVE-2012-4146)

See also :

http://www.opera.com/support/kb/view/1016/
http://www.opera.com/support/kb/view/1025/
http://www.opera.com/support/kb/view/1026/
http://www.opera.com/support/kb/view/1027/
http://www.opera.com/docs/changelogs/windows/1201

Solution :

Upgrade to Opera 12.01 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now