Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscriptions and read the contents of arbitrary feeds.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/32394 | third party advisory vendor advisory |
http://www.opera.com/docs/changelogs/mac/961/ | |
http://www.vupen.com/english/advisories/2008/2873 | vdb entry |
http://www.openwall.com/lists/oss-security/2008/10/21/6 | mailing list |
http://www.opera.com/support/search/view/905/ | |
http://secunia.com/advisories/32538 | third party advisory vendor advisory |
http://secunia.com/advisories/32299 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46005 | vdb entry |
http://www.opera.com/docs/changelogs/solaris/961/ | |
http://www.openwall.com/lists/oss-security/2008/10/22/5 | mailing list |
http://www.opera.com/docs/changelogs/windows/961/ | |
http://www.opera.com/docs/changelogs/linux/961/ | |
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00009.html | vendor advisory |
http://www.opera.com/docs/changelogs/freebsd/961/ | |
http://www.securityfocus.com/bid/31842 | vdb entry |
http://security.gentoo.org/glsa/glsa-200811-01.xml | vendor advisory |