Summary: | <www-client/opera-12.01.1532 - multiple vulnerabilities (CVE-2012-{4142,4143,4144,4145,4146}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Jeroen Roovers (RETIRED) <jer> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.opera.com/docs/changelogs/unix/1201/ | ||
Whiteboard: | B2 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Jeroen Roovers (RETIRED)
2012-08-02 12:24:57 UTC
amd64 stable x86 stable Thanks, everyone. GLSA request filed. CVE-2012-4146 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4146): Opera before 12.01 allows remote attackers to cause a denial of service (application crash) via a crafted web site, as demonstrated by the Lenovo "Shop now" page. CVE-2012-4145 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4145): Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue." CVE-2012-4144 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4144): Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted HTML document. CVE-2012-4143 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4143): Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog, a different vulnerability than CVE-2012-1924. CVE-2012-4142 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4142): Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, ignores some characters in HTML documents in unspecified circumstances, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document. This issue was resolved and addressed in GLSA 201209-11 at http://security.gentoo.org/glsa/glsa-201209-11.xml by GLSA coordinator Sean Amoss (ackle). |