CVE Vulnerabilities

CVE-2008-4694

Improper Link Resolution Before File Access ('Link Following')

Published: Oct 23, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a crafted URL.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

Name Vendor Start Version End Version
Opera_browser Opera * 9.60 (including)
Opera_browser Opera 5.0 (including) 5.0 (including)
Opera_browser Opera 5.0-beta2 (including) 5.0-beta2 (including)
Opera_browser Opera 5.0-beta3 (including) 5.0-beta3 (including)
Opera_browser Opera 5.0-beta4 (including) 5.0-beta4 (including)
Opera_browser Opera 5.0-beta5 (including) 5.0-beta5 (including)
Opera_browser Opera 5.0-beta6 (including) 5.0-beta6 (including)
Opera_browser Opera 5.0-beta7 (including) 5.0-beta7 (including)
Opera_browser Opera 5.0-beta8 (including) 5.0-beta8 (including)
Opera_browser Opera 5.02 (including) 5.02 (including)
Opera_browser Opera 5.10 (including) 5.10 (including)
Opera_browser Opera 5.11 (including) 5.11 (including)
Opera_browser Opera 5.12 (including) 5.12 (including)
Opera_browser Opera 6.0 (including) 6.0 (including)
Opera_browser Opera 6.0-beta1 (including) 6.0-beta1 (including)
Opera_browser Opera 6.0-beta2 (including) 6.0-beta2 (including)
Opera_browser Opera 6.0-beta3 (including) 6.0-beta3 (including)
Opera_browser Opera 6.0-tp1 (including) 6.0-tp1 (including)
Opera_browser Opera 6.0-tp2 (including) 6.0-tp2 (including)
Opera_browser Opera 6.0-tp3 (including) 6.0-tp3 (including)
Opera_browser Opera 6.1 (including) 6.1 (including)
Opera_browser Opera 6.01 (including) 6.01 (including)
Opera_browser Opera 6.1-beta1 (including) 6.1-beta1 (including)
Opera_browser Opera 6.02 (including) 6.02 (including)
Opera_browser Opera 6.03 (including) 6.03 (including)
Opera_browser Opera 6.04 (including) 6.04 (including)
Opera_browser Opera 6.05 (including) 6.05 (including)
Opera_browser Opera 6.06 (including) 6.06 (including)
Opera_browser Opera 6.11 (including) 6.11 (including)
Opera_browser Opera 6.12 (including) 6.12 (including)
Opera_browser Opera 7.0 (including) 7.0 (including)
Opera_browser Opera 7.0-beta1 (including) 7.0-beta1 (including)
Opera_browser Opera 7.0-beta1_v2 (including) 7.0-beta1_v2 (including)
Opera_browser Opera 7.0-beta2 (including) 7.0-beta2 (including)
Opera_browser Opera 7.01 (including) 7.01 (including)
Opera_browser Opera 7.02 (including) 7.02 (including)
Opera_browser Opera 7.03 (including) 7.03 (including)
Opera_browser Opera 7.10 (including) 7.10 (including)
Opera_browser Opera 7.10-beta1 (including) 7.10-beta1 (including)
Opera_browser Opera 7.11 (including) 7.11 (including)
Opera_browser Opera 7.11-beta2 (including) 7.11-beta2 (including)
Opera_browser Opera 7.20 (including) 7.20 (including)
Opera_browser Opera 7.20-beta7 (including) 7.20-beta7 (including)
Opera_browser Opera 7.21 (including) 7.21 (including)
Opera_browser Opera 7.22 (including) 7.22 (including)
Opera_browser Opera 7.23 (including) 7.23 (including)
Opera_browser Opera 7.50 (including) 7.50 (including)
Opera_browser Opera 7.50-beta1 (including) 7.50-beta1 (including)
Opera_browser Opera 7.51 (including) 7.51 (including)
Opera_browser Opera 7.52 (including) 7.52 (including)
Opera_browser Opera 7.53 (including) 7.53 (including)
Opera_browser Opera 7.54 (including) 7.54 (including)
Opera_browser Opera 7.54-update1 (including) 7.54-update1 (including)
Opera_browser Opera 7.54-update2 (including) 7.54-update2 (including)
Opera_browser Opera 7.60 (including) 7.60 (including)
Opera_browser Opera 8.0 (including) 8.0 (including)
Opera_browser Opera 8.0-beta1 (including) 8.0-beta1 (including)
Opera_browser Opera 8.0-beta2 (including) 8.0-beta2 (including)
Opera_browser Opera 8.0-beta3 (including) 8.0-beta3 (including)
Opera_browser Opera 8.01 (including) 8.01 (including)
Opera_browser Opera 8.02 (including) 8.02 (including)
Opera_browser Opera 8.50 (including) 8.50 (including)
Opera_browser Opera 8.51 (including) 8.51 (including)
Opera_browser Opera 8.52 (including) 8.52 (including)
Opera_browser Opera 8.53 (including) 8.53 (including)
Opera_browser Opera 8.54 (including) 8.54 (including)
Opera_browser Opera 9.0 (including) 9.0 (including)
Opera_browser Opera 9.0-beta1 (including) 9.0-beta1 (including)
Opera_browser Opera 9.0-beta2 (including) 9.0-beta2 (including)
Opera_browser Opera 9.01 (including) 9.01 (including)
Opera_browser Opera 9.02 (including) 9.02 (including)
Opera_browser Opera 9.10 (including) 9.10 (including)
Opera_browser Opera 9.12 (including) 9.12 (including)
Opera_browser Opera 9.20 (including) 9.20 (including)
Opera_browser Opera 9.20-beta1 (including) 9.20-beta1 (including)
Opera_browser Opera 9.21 (including) 9.21 (including)
Opera_browser Opera 9.22 (including) 9.22 (including)
Opera_browser Opera 9.23 (including) 9.23 (including)
Opera_browser Opera 9.24 (including) 9.24 (including)
Opera_browser Opera 9.25 (including) 9.25 (including)
Opera_browser Opera 9.26 (including) 9.26 (including)
Opera_browser Opera 9.27 (including) 9.27 (including)
Opera_browser Opera 9.50 (including) 9.50 (including)
Opera_browser Opera 9.50-beta1 (including) 9.50-beta1 (including)
Opera_browser Opera 9.50-beta2 (including) 9.50-beta2 (including)
Opera_browser Opera 9.51 (including) 9.51 (including)
Opera_browser Opera 9.52 (including) 9.52 (including)

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References