CVE-2007-6524

Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420.
References
Link Resource
http://bugs.gentoo.org/show_bug.cgi?id=202770
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00001.html
http://osvdb.org/42691
http://secunia.com/advisories/28169 Patch Vendor Advisory
http://secunia.com/advisories/28290 Vendor Advisory
http://secunia.com/advisories/28314 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200712-22.xml
http://securitytracker.com/id?1019435
http://www.opera.com/docs/changelogs/linux/925/
http://www.opera.com/docs/changelogs/windows/925/ Patch
http://www.opera.com/support/search/view/876/
http://www.securityfocus.com/archive/1/488264/100/0/threaded
http://www.securityfocus.com/bid/26937
http://www.securitytracker.com/id?1019131
http://www.vupen.com/english/advisories/2007/4261 Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=408076
https://exchange.xforce.ibmcloud.com/vulnerabilities/39163
http://bugs.gentoo.org/show_bug.cgi?id=202770
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00001.html
http://osvdb.org/42691
http://secunia.com/advisories/28169 Patch Vendor Advisory
http://secunia.com/advisories/28290 Vendor Advisory
http://secunia.com/advisories/28314 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200712-22.xml
http://securitytracker.com/id?1019435
http://www.opera.com/docs/changelogs/linux/925/
http://www.opera.com/docs/changelogs/windows/925/ Patch
http://www.opera.com/support/search/view/876/
http://www.securityfocus.com/archive/1/488264/100/0/threaded
http://www.securityfocus.com/bid/26937
http://www.securitytracker.com/id?1019131
http://www.vupen.com/english/advisories/2007/4261 Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=408076
https://exchange.xforce.ibmcloud.com/vulnerabilities/39163
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta4:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta5:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta6:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta7:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.0:beta8:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:5.12:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:tp1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:tp2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.0:tp3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.1:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.1:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.03:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.04:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.05:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.06:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:6.12:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:beta1_v2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.03:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.10:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.11:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.11:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.20:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.20:beta7:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.21:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.22:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.23:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.50:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.51:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.52:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.53:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.54:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.54:update1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.54:update2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:7.60:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.50:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.51:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.52:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.53:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:8.54:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.0:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.0:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.0:beta2:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.01:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.02:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.10:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.12:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.20:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.20:beta1:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.21:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.22:*:*:*:*:*:*:*
cpe:2.3:a:opera:opera_browser:9.23:*:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://bugs.gentoo.org/show_bug.cgi?id=202770 - () http://bugs.gentoo.org/show_bug.cgi?id=202770 -
References () http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00001.html -
References () http://osvdb.org/42691 - () http://osvdb.org/42691 -
References () http://secunia.com/advisories/28169 - Patch, Vendor Advisory () http://secunia.com/advisories/28169 - Patch, Vendor Advisory
References () http://secunia.com/advisories/28290 - Vendor Advisory () http://secunia.com/advisories/28290 - Vendor Advisory
References () http://secunia.com/advisories/28314 - Vendor Advisory () http://secunia.com/advisories/28314 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200712-22.xml - () http://security.gentoo.org/glsa/glsa-200712-22.xml -
References () http://securitytracker.com/id?1019435 - () http://securitytracker.com/id?1019435 -
References () http://www.opera.com/docs/changelogs/linux/925/ - () http://www.opera.com/docs/changelogs/linux/925/ -
References () http://www.opera.com/docs/changelogs/windows/925/ - Patch () http://www.opera.com/docs/changelogs/windows/925/ - Patch
References () http://www.opera.com/support/search/view/876/ - () http://www.opera.com/support/search/view/876/ -
References () http://www.securityfocus.com/archive/1/488264/100/0/threaded - () http://www.securityfocus.com/archive/1/488264/100/0/threaded -
References () http://www.securityfocus.com/bid/26937 - () http://www.securityfocus.com/bid/26937 -
References () http://www.securitytracker.com/id?1019131 - () http://www.securitytracker.com/id?1019131 -
References () http://www.vupen.com/english/advisories/2007/4261 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/4261 - Vendor Advisory
References () https://bugzilla.mozilla.org/show_bug.cgi?id=408076 - () https://bugzilla.mozilla.org/show_bug.cgi?id=408076 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/39163 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/39163 -

Information

Published : 2007-12-24 20:46

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6524

Mitre link : CVE-2007-6524

CVE.ORG link : CVE-2007-6524


JSON object : View

Products Affected

opera

  • opera_browser
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor