CERTA-2004-AVI-165
Vulnerability from certfr_avis
Une vulnérabilité du navigateur Opera permet à un utilisateur distant mal intentionné de supprimer des fichiers.
Description
Opera est un navigateur web disponible pour plusieurs plates-formes.
Une vulnérabilité a été découverte dans la gestion du service telnet.
Elle permet à un utilisateur distant mal intentionné, via un lien
malicieusement construit, d'écraser des fichiers avec les droits de
l'utilisateur courant.
Contournement provisoire
Désactiver le service telnet sous Opera.
Solution
La version 7.50 corrige cette vulnérabilité.
Opera 7.x.
Impacted products
| Vendor | Product | Description |
|---|
References
| Title | Publication Time | Tags | |
|---|---|---|---|
|
|
|||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [],
"affected_systems_content": "\u003cp\u003eOpera 7.x.\u003c/p\u003e",
"content": "## Description\n\nOpera est un navigateur web disponible pour plusieurs plates-formes. \nUne vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans la gestion du service telnet.\nElle permet \u00e0 un utilisateur distant mal intentionn\u00e9, via un lien\nmalicieusement construit, d\u0027\u00e9craser des fichiers avec les droits de\nl\u0027utilisateur courant.\n\n## Contournement provisoire\n\nD\u00e9sactiver le service telnet sous Opera.\n\n## Solution\n\nLa version 7.50 corrige cette vuln\u00e9rabilit\u00e9.\n",
"cves": [],
"initial_release_date": "2004-05-13T00:00:00",
"last_revision_date": "2004-05-27T00:00:00",
"links": [
{
"title": "Site Internet du navigateur Opera :",
"url": "http://www.opera.com"
},
{
"title": "Mise \u00e0 jour de s\u00e9curit\u00e9 du paquetage NetBSD Opera :",
"url": "ftp://ftp.netbsd.org/pub/NetBSD/packages/pkgsrc/www/opera7/README.html"
},
{
"title": "Bulletin de s\u00e9curit\u00e9 pour le paquetage OpenBSD Opera du 15 mai 2004 :",
"url": "http://www.vuxml.org/openbsd/"
},
{
"title": "Bulletin de s\u00e9curit\u00e9 Gentoo GLSA 200405-19 du 25 mai 2004 :",
"url": "http://security.gentoo.org/glsa/glsa-200405-19.xml"
},
{
"title": "Bulletin de s\u00e9curit\u00e9 iDefense du 12 mai 2004 :",
"url": "http://www.idefense.com/application/poi/display?id=104\u0026type=vulnerabilities"
}
],
"reference": "CERTA-2004-AVI-165",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2004-05-13T00:00:00.000000"
},
{
"description": "correction de la r\u00e9f\u00e9rence \u00e0 l\u0027avis de s\u00e9curit\u00e9 iDefense, ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 NetBSD.",
"revision_date": "2004-05-14T00:00:00.000000"
},
{
"description": "correction de la r\u00e9f\u00e9rence \u00e0 l\u0027avis de s\u00e9curit\u00e9 NetBSD.",
"revision_date": "2004-05-17T00:00:00.000000"
},
{
"description": "ajout de l\u0027avis de s\u00e9curit\u00e9 Gentoo.",
"revision_date": "2004-05-26T00:00:00.000000"
},
{
"description": "ajout de la r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 OpenBSD.",
"revision_date": "2004-05-27T00:00:00.000000"
}
],
"risks": [
{
"description": "Suppression de fichiers"
}
],
"summary": "Une vuln\u00e9rabilit\u00e9 du navigateur Opera permet \u00e0 un utilisateur distant\nmal intentionn\u00e9 de supprimer des fichiers.\n",
"title": "Vuln\u00e9rabilit\u00e9 du navigateur Opera",
"vendor_advisories": [
{
"published_at": null,
"title": "Avis de s\u00e9curit\u00e9 iDefense du 12 mai 2004",
"url": null
}
]
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…