Korean
<< Back
VID 28826
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Opera web browser which is older than version 11.00 has been installed on the host. Opera is a Web browser, developed by Opera Software, for multiple operating systems. Opera versions prior to 11.00 are vulnerable to multiple vulnerabilities.

- An error exists such that web page content can be displayed over dialog boxes leading to security warning misrepresentation. (977, CVE-2010-4579))

- An error exists such that WAP form contents can be leaked to third-party sites. (979, CVE-2010-4580)

- An unspecified high severity issue with unknown impact exists. (CVE-2010-4581)

- An error exists in the handling of security policies during extension updates. (CVE-2010-4582)

- An error exists when 'Opera Turbo' is enabled which does not display a page's security information correctly. (CVE-2010-4583)

- An error exists when viewing sites over HTTPS such that problems with X.509 certificates are not displayed properly. (CVE-2010-4584)

- An error exists in the automatic update functionality which allows an attacker to cause a denial of service by crashing the application. (CVE-2010-4585)

- The 'WebSockets' implementation contains unspecified errors with unknown impact. (CVE-2010-4586)

- An error exists in the implementation of the 'Insecure Third Party Module' warning messages results in an unspecified vulnerability. (CVE-2010-4587)

* References:
http://www.opera.com/docs/changelogs/windows/1100/
http://www.opera.com/support/kb/view/977/
http://www.opera.com/support/kb/view/979/

* Platforms Affected:
Opera Software, Opera versions prior to 11.00
Recommendation Upgrade to the latest version of Opera (11.00 or later), available from the Opera Web site at http://www.opera.com/download/
Related URL CVE-2010-4579,CVE-2010-4580,CVE-2010-4581,CVE-2010-4582,CVE-2010-4583,CVE-2010-4584,CVE-2010-4585,CVE-2010-4586,CVE-2010-4587 (CVE)
Related URL 45461 (SecurityFocus)
Related URL (ISS)