CVE Vulnerabilities

CVE-2019-18624

Published: Oct 29, 2019 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.

Affected Software

Name Vendor Start Version End Version
Mini Opera 44.1.2254.142553 (including) 44.1.2254.142553 (including)
Mini Opera 44.1.2254.142659 (including) 44.1.2254.142659 (including)
Mini Opera 44.1.2254.143214 (including) 44.1.2254.143214 (including)

References