Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
http://www.opera.com/linux/changelogs/754u1/ | broken link |
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html | mailing list exploit |
http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml | third party advisory patch vendor advisory |