Opera before 11.01 does not properly restrict the use of opera: URLs, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.opera.com/docs/changelogs/windows/1101/ | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11641 | vdb entry signature |
http://www.opera.com/support/kb/view/983/ | vendor advisory |
http://www.vupen.com/english/advisories/2011/0231 | vdb entry |
http://www.opera.com/docs/changelogs/unix/1101/ | |
http://www.securityfocus.com/bid/46036 | vdb entry |
http://www.opera.com/docs/changelogs/mac/1101/ | |
http://osvdb.org/70729 | vdb entry |
http://secunia.com/advisories/43023 | third party advisory |