Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
References
Link | Resource |
---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html | Exploit |
http://www.opera.com/linux/changelogs/754u1/ | Broken Link |
http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml | Patch Third Party Advisory |
Configurations
Information
Published : 2004-12-30 21:00
Updated : 2022-02-28 10:04
NVD link : CVE-2004-1489
Mitre link : CVE-2004-1489
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
opera
- opera_browser