Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 464632 - <www-client/opera-12.15_p1748 - multiple vulnerabilities (CVE-2013-{3210,3211})
Summary: <www-client/opera-12.15_p1748 - multiple vulnerabilities (CVE-2013-{3210,3211})
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/52859/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-04-04 19:08 UTC by Agostino Sarubbo
Modified: 2013-08-22 10:57 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-04-04 19:08:48 UTC
From ${URL} :

Description
A weakness and a vulnerability have been reported in Opera, where one has an unknown impact and the other can be exploited by malicious people to disclose potentially 
sensitive information.

1) The weakness is caused due to the application allowing cookies to be set for top-level domains, which may lead to the cookie being exposed to other websites under the 
same top-level domain.

2) An unspecified error exists. No further information is currently available.

The weakness and a vulnerability are reported in version 12.14. Prior versions may also be affected.


Solution
Update to version 12.15.

Provided and/or discovered by
1) Reported by the vendor
2) The vendor credits Attila Suszter

Original Advisory
Opera:
http://www.opera.com/docs/changelogs/unified/1215/
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2013-04-05 09:35:54 UTC
 * Fixed a moderately severe issue, as reported by Attila Suszter; details will
   be disclosed at a later date.
 * Added safeguards against attacks on the RC4 encryption protocol; see our
   advisory[1].
 * Fixed an issue where cookies could be set for a top-level domain; see our
   advisory[2].

[1] http://www.opera.com/security/advisory/1046
[2] http://www.opera.com/security/advisory/1047
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2013-04-05 09:40:08 UTC
Arch teams, please test and mark stable:
=www-client/opera-12.15_p1748
Stable KEYWORDS : amd64 x86
Comment 3 Agostino Sarubbo gentoo-dev 2013-04-05 14:18:50 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-04-05 14:19:13 UTC
x86 stable
Comment 5 Sean Amoss (RETIRED) gentoo-dev Security 2013-04-06 20:25:58 UTC
GLSA vote: no.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2013-04-19 16:00:26 UTC
CVE-2013-3211 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3211):
  Unspecified vulnerability in Opera before 12.15 has unknown impact and
  attack vectors, related to a "moderately severe issue."

CVE-2013-3210 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3210):
  Opera before 12.15 does not properly block top-level domains in Set-Cookie
  headers, which allows remote attackers to obtain sensitive information by
  leveraging control of a different web site in the same top-level domain.
Comment 7 Sergey Popov gentoo-dev 2013-08-22 10:57:34 UTC
GLSA vote: no

Closing as noglsa