VID |
28826 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Opera web browser which is older than version 11.00 has been installed on the host. Opera is a Web browser, developed by Opera Software, for multiple operating systems. Opera versions prior to 11.00 are vulnerable to multiple vulnerabilities.
- An error exists such that web page content can be displayed over dialog boxes leading to security warning misrepresentation. (977, CVE-2010-4579))
- An error exists such that WAP form contents can be leaked to third-party sites. (979, CVE-2010-4580)
- An unspecified high severity issue with unknown impact exists. (CVE-2010-4581)
- An error exists in the handling of security policies during extension updates. (CVE-2010-4582)
- An error exists when 'Opera Turbo' is enabled which does not display a page's security information correctly. (CVE-2010-4583)
- An error exists when viewing sites over HTTPS such that problems with X.509 certificates are not displayed properly. (CVE-2010-4584)
- An error exists in the automatic update functionality which allows an attacker to cause a denial of service by crashing the application. (CVE-2010-4585)
- The 'WebSockets' implementation contains unspecified errors with unknown impact. (CVE-2010-4586)
- An error exists in the implementation of the 'Insecure Third Party Module' warning messages results in an unspecified vulnerability. (CVE-2010-4587)
* References: http://www.opera.com/docs/changelogs/windows/1100/ http://www.opera.com/support/kb/view/977/ http://www.opera.com/support/kb/view/979/
* Platforms Affected: Opera Software, Opera versions prior to 11.00 |
Recommendation |
Upgrade to the latest version of Opera (11.00 or later), available from the Opera Web site at http://www.opera.com/download/ |
Related URL |
CVE-2010-4579,CVE-2010-4580,CVE-2010-4581,CVE-2010-4582,CVE-2010-4583,CVE-2010-4584,CVE-2010-4585,CVE-2010-4586,CVE-2010-4587 (CVE) |
Related URL |
45461 (SecurityFocus) |
Related URL |
(ISS) |
|