Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 308069 (CVE-2010-0653) - <www-client/opera-10.10: cross-origin CSS information leak (CVE-2010-0653)
Summary: <www-client/opera-10.10: cross-origin CSS information leak (CVE-2010-0653)
Status: RESOLVED FIXED
Alias: CVE-2010-0653
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: B4 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-03-06 15:56 UTC by Stefan Behte (RETIRED)
Modified: 2012-06-15 17:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-03-06 15:56:07 UTC
CVE-2010-0653 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0653):
  Opera permits cross-origin loading of CSS stylesheets even when the
  stylesheet download has an incorrect MIME type and the stylesheet
  document is malformed, which allows remote HTTP servers to obtain
  sensitive information via a crafted document.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2010-07-02 16:55:47 UTC
I thought this vuln might be related to [1] (fixed in 10.11), but that seems to be a much wider issue. Note that the [URL]'s reference[2] mentions Opera and practically all other browsers only in the description at the top of the report, and there's one comment mentioning Opera again. Webkit and IE fixes are discussed but nothing about (talking to) Opera.


[1] http://www.opera.com/support/kb/view/955/
[2] http://code.google.com/p/chromium/issues/detail?id=9877
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-03-09 23:08:59 UTC
Added to existing GLSA request.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2012-06-15 17:40:30 UTC
This issue was resolved and addressed in
 GLSA 201206-03 at http://security.gentoo.org/glsa/glsa-201206-03.xml
by GLSA coordinator Sean Amoss (ackle).