VulDB: Opera Browser up to 7.51 Favicon Address Bar Handler Designfehler
General

scipID: 688
Affected: Opera Browser up to 7.51
Published: 06/03/2004 (GreyMagic)
Risk:
problematic
Entry: 94.5% complete
Created: 06/07/2004
Updated: 09/03/2012
Summary
A vulnerability has been found in Opera Browser up to 7.51 and classified as problematic. This vulnerability affects an unknown function of the component Favicon Address Bar Handler. The manipulation with an unknown input leads to a designfehler vulnerability. The impact remains unknown.
The weakness was presented 06/03/2004 by GreyMagic. The advisory is shared for download at securityfocus.com. This vulnerability was named CVE-2004-0537 since 06/04/2004. The attack can be initiated remotely. Technical details are unknown but an exploit is available.
The exploit is shared for download at securityfocus.com. The vulnerability scanner Nessus provides a plugin with the ID 14245 (Opera < 7.51 favicon.ico Address Bar Spoofing), which helps to determine the existence of the flaw in a target environment. It is assigned to the family Windows and running in the context local.
Applying a patch is able to eliminate this problem. The bugfix is ready for download at opera.com. The vulnerability is also documented in the databases at OSVDB (6590), Secunia (SA11762), SecurityFocus (BID 10452) and X-Force (16307). Additional details are provided at opera.com.CVSS
Base Score: 4.6 (CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:P) [?]
| Access Vector | Access Complexity | Authentication | Confidentiality | Integrity | Availability |
|---|---|---|---|---|---|
| Local | High | Multiple | None | None | None |
| Adjacent | Medium | Single | Partial | Partial | Partial |
| Network | Low | None | Complete | Complete | Complete |
Exploiting
Class: Designfehler
Local: No
Remote: Yes
Availability: Yes
Download: securityfocus.com
Nessus ID: 14245
Nessus Name: Opera < 7.51 favicon.ico Address Bar Spoofing
Nessus Risk: Medium
Nessus Family: Windows
Nessus Context: local
Countermeasures
Recommended: Upgrade
0-Day Time: 0 days since found
Patch: opera.com
Timeline
06/03/2004 | Advisory disclosed
06/03/2004 | OSVDB entry created
06/04/2004 | CVE assigned
06/07/2004 | VulDB entry created
08/10/2004 | Nessus plugin released
09/03/2012 | VulDB entry updated
Sources
Advisory: securityfocus.com
Researcher: GreyMagic
Confirmation: opera.com
OSVDB: 6590
CVE: CVE-2004-0537 (mitre.org) (nist.org) (cvedetails.com)
Secunia: 11762
SecurityFocus: 10452
X-Force: 16307
Misc.: opera.com



















