FreeBSD : opera -- multiple vulnerabilities (d6b092bd-61e1-11da-b64c-0001020eed82)

Medium Nessus Plugin ID 21517


The remote FreeBSD host is missing one or more security-related updates.


Opera reports :

It is possible to make a form input that looks like an image link. If the form input has a 'title' attribute, the status bar will show the 'title'. A 'title' which looks like a URL can mislead the user, since the title can say, while the form action can be something else.

Opera's tooltip says 'Title:' before the title text, making a spoof URL less convincing. A user who has enabled the status bar and disabled tooltips can be affected by this. Neither of these settings are Opera's defaults.

This exploit is mostly of interest to users who disable JavaScript. If JavaScript is enabled, any link target or form action can be overridden by the script. The tooltip and the statusbar can only be trusted to show the true location if JavaScript is disabled.

Java code using LiveConnect methods to remove a property of a JavaScript object may in some cases use NULL pointers that can make Opera crash. This crash is not exploitable and such code is rare on the web.


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 21517

File Name: freebsd_pkg_d6b092bd61e111dab64c0001020eed82.nasl

Version: $Revision: 1.11 $

Type: local

Published: 2006/05/13

Modified: 2014/08/20

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:linux-opera, p-cpe:/a:freebsd:freebsd:opera, p-cpe:/a:freebsd:freebsd:opera-devel, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2005/11/30

Vulnerability Publication Date: 2005/11/16

Reference Information

CVE: CVE-2005-3699

Secunia: 17571