Opera before 10.60 on Windows and Mac OS X does not properly prevent certain double-click operations from running a program located on a web site, which allows user-assisted remote attackers to execute arbitrary code via a crafted web page that bypasses a dialog.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/40375 | third party advisory |
http://www.opera.com/docs/changelogs/mac/1060/ | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11856 | vdb entry third party advisory signature |
http://www.opera.com/support/search/view/957/ | vendor advisory |
http://www.vupen.com/english/advisories/2010/1664 | permissions required vdb entry third party advisory |
http://www.opera.com/docs/changelogs/windows/1060/ | vendor advisory |