OSVDB ID: 19509

Title: Opera Mail Client Crafted Content-Type File Extension Spoofing

Info

Disclosure

Sep 20, 2005

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Opera contains a flaw that may allow a remote user to spoof file types and cause a target user to execute arbitrary code. The issue is triggered when an additional '.' is appended to the end of a filename, which could allow an extension to be spoofed. It is possible that the flaw may allow a script insertion attack, if the user chooses to view an attachment resulting in a loss of confidentiality.

Classification

Location: Local Access Required, Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored

Solution

Upgrade to version 8.50 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Opera Software ASA

Opera

8.02

References

Credit

  • Jakob Balle - jbsecunia.com - Secunia Research


Direct URL: http://osvdb.org/19509