Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 386217 - <www-client/opera-9.52: Multiple vulnerabilities (CVE-2010-{1989,1993,2121})
Summary: <www-client/opera-9.52: Multiple vulnerabilities (CVE-2010-{1989,1993,2121})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-08 01:09 UTC by GLSAMaker/CVETool Bot
Modified: 2012-06-15 17:41 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 01:09:20 UTC
CVE-2010-1989 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1989):
  Opera 9.52 executes a mail application in situations where an IMG element
  has a SRC attribute that is a redirect to a mailto: URL, which allows remote
  attackers to cause a denial of service (excessive application launches) via
  an HTML document with many images, a related issue to CVE-2010-0181.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-10-08 01:15:51 UTC
CVE-2010-2121 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2121):
  Opera 9.52 allows remote attackers to cause a denial of service (resource
  consumption) via JavaScript code containing an infinite loop that creates
  IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2012-06-15 17:41:19 UTC
This issue was resolved and addressed in
 GLSA 201206-03 at http://security.gentoo.org/glsa/glsa-201206-03.xml
by GLSA coordinator Sean Amoss (ackle).