Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash).
Link | Tags |
---|---|
http://marc.info/?l=full-disclosure&m=103783186608438&w=2 | mailing list |
http://www.securityfocus.com/bid/6218 | vdb entry |
http://www.iss.net/security_center/static/10673.php | vdb entry |