LWN.net Logo

opera: multiple vulnerabilities

Package(s):opera CVE #(s):CVE-2010-0653 CVE-2010-1993
Created:July 14, 2010 Updated:August 2, 2010
Description: From the openSUSE advisory:

CVE-2010-0653: Opera permits cross-origin loading of CSS style sheets even when the style sheet download has an incorrect MIME type and the style sheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document.

CVE-2010-1993: Opera 9.52 does not properly handle an IFRAME element with a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (resource consumption) via an HTML document with many IFRAME elements.

Alerts:
SUSE SUSE-SR:2010:014 2010-08-02
openSUSE openSUSE-SU-2010:0422-1 2010-07-22
openSUSE openSUSE-SU-2010:0370-1 2010-07-14
openSUSE openSUSE-SU-2010:0368-1 2010-07-14
Gentoo 201206-03 2012-06-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds