Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
References
Link | Resource |
---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html | Exploit |
http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml | Patch Third Party Advisory |
http://www.opera.com/linux/changelogs/754u1/ | Broken Link |
Configurations
History
No history.
Information
Published : 2004-12-31 05:00
Updated : 2024-02-28 10:24
NVD link : CVE-2004-1489
Mitre link : CVE-2004-1489
CVE.ORG link : CVE-2004-1489
JSON object : View
Products Affected
opera
- opera_browser
CWE
CWE-668
Exposure of Resource to Wrong Sphere