ID

VAR-201208-0205


CVE

CVE-2012-4145


TITLE

Opera Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2012-003481

DESCRIPTION

Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue.". Opera Contains vulnerabilities that are unspecified.It may be affected unspecified. Little is known about this issue or its effects at this time. We will update this BID as more information emerges. It supports multi-window browsing and a customizable user interface. Unidentified vulnerabilities exist in Opera versions prior to 12.01 on Windows and UNIX systems, Opera versions prior to 11.66 on Mac OS X-based systems, and Opera versions prior to 12.01. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201209-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Opera: Multiple vulnerabilities Date: September 25, 2012 Bugs: #429478, #434584 ID: 201209-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in Opera, the worst of which may allow remote execution of arbitrary code. Please review the CVE identifiers and Opera Release Notes referenced below for details. Impact ====== A remote attacker could entice a user to open a specially crafted web page using Opera, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Furthermore, a remote attacker may be able to trick a user into downloading and executing files, conduct Cross-Site Scripting (XSS) attacks, spoof the address bar, or have other unspecified impact. Resolution ========== All Opera users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/opera-12.01.1532" References ========== [ 1 ] CVE-2012-4010 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4010 [ 2 ] CVE-2012-4142 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4142 [ 3 ] CVE-2012-4143 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4143 [ 4 ] CVE-2012-4144 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4144 [ 5 ] CVE-2012-4145 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4145 [ 6 ] CVE-2012-4146 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4146 [ 7 ] Opera 12.01 for UNIX changelog http://www.opera.com/docs/changelogs/unix/1201/ Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201209-11.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5

Trust: 2.16

sources: NVD: CVE-2012-4145 // JVNDB: JVNDB-2012-003481 // BID: 54780 // VULHUB: VHN-57426 // VULMON: CVE-2012-4145 // PACKETSTORM: 116866

AFFECTED PRODUCTS

vendor:operamodel:browserscope:eqversion:10.00

Trust: 1.6

vendor:operamodel:browserscope:eqversion:12.00

Trust: 1.6

vendor:operamodel:browserscope:eqversion:10.62

Trust: 1.6

vendor:operamodel:browserscope:eqversion:10.60

Trust: 1.6

vendor:operamodel:browserscope:eqversion:10.61

Trust: 1.6

vendor:operamodel:browserscope:eqversion:10.63

Trust: 1.6

vendor:operamodel:browserscope:eqversion:10.53

Trust: 1.6

vendor:operamodel:browserscope:eqversion:10.54

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.60

Trust: 1.0

vendor:operamodel:browserscope:eqversion:10.50

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.01

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.00

Trust: 1.0

vendor:operamodel:browserscope:eqversion:10.51

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.51

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.52

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.11

Trust: 1.0

vendor:operamodel:browserscope:eqversion:10.10

Trust: 1.0

vendor:operamodel:browserscope:eqversion:10.01

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.10

Trust: 1.0

vendor:operamodel:browserscope:lteversion:12.00

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.52.1100

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.50

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.61

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.62

Trust: 1.0

vendor:operamodel:browserscope:lteversion:11.65

Trust: 1.0

vendor:operamodel:browserscope:eqversion:10.11

Trust: 1.0

vendor:operamodel:browserscope:eqversion:11.64

Trust: 1.0

vendor:operamodel:browserscope:eqversion:10.52

Trust: 1.0

vendor:opera asamodel:operascope:ltversion:12. x

Trust: 0.8

vendor:opera asamodel:operascope:eqversion:12.01

Trust: 0.8

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

sources: BID: 54780 // JVNDB: JVNDB-2012-003481 // CNNVD: CNNVD-201208-023 // NVD: CVE-2012-4145

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-4145
value: HIGH

Trust: 1.0

NVD: CVE-2012-4145
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201208-023
value: CRITICAL

Trust: 0.6

VULHUB: VHN-57426
value: HIGH

Trust: 0.1

VULMON: CVE-2012-4145
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2012-4145
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-57426
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-57426 // VULMON: CVE-2012-4145 // JVNDB: JVNDB-2012-003481 // CNNVD: CNNVD-201208-023 // NVD: CVE-2012-4145

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2012-4145

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 116866 // CNNVD: CNNVD-201208-023

TYPE

Unknown

Trust: 0.3

sources: BID: 54780

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-003481

PATCH

title:Opera 12.01 for UNIX changelogurl:http://www.opera.com/docs/changelogs/unix/1201/

Trust: 0.8

title:Opera 12.01 for Mac changelogurl:http://www.opera.com/docs/changelogs/mac/1201/

Trust: 0.8

title:Opera 11.66 for Mac changelogurl:http://www.opera.com/docs/changelogs/mac/1166/

Trust: 0.8

title:Opera 12.01 for Windows changelogurl:http://www.opera.com/docs/changelogs/windows/1201/

Trust: 0.8

sources: JVNDB: JVNDB-2012-003481

EXTERNAL IDS

db:NVDid:CVE-2012-4145

Trust: 3.0

db:JVNDBid:JVNDB-2012-003481

Trust: 0.8

db:CNNVDid:CNNVD-201208-023

Trust: 0.7

db:BIDid:54780

Trust: 0.5

db:VULHUBid:VHN-57426

Trust: 0.1

db:VULMONid:CVE-2012-4145

Trust: 0.1

db:PACKETSTORMid:116866

Trust: 0.1

sources: VULHUB: VHN-57426 // VULMON: CVE-2012-4145 // BID: 54780 // JVNDB: JVNDB-2012-003481 // PACKETSTORM: 116866 // CNNVD: CNNVD-201208-023 // NVD: CVE-2012-4145

REFERENCES

url:http://www.opera.com/docs/changelogs/unix/1201/

Trust: 1.9

url:http://www.opera.com/docs/changelogs/mac/1166/

Trust: 1.8

url:http://www.opera.com/docs/changelogs/mac/1201/

Trust: 1.8

url:http://www.opera.com/docs/changelogs/windows/1201/

Trust: 1.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-4145

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-4145

Trust: 0.8

url:http://www.opera.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://www.securityfocus.com/bid/54780

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4143

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4146

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4145

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4144

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201209-11.xml

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4142

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4010

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4142

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4145

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4010

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4144

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4143

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-4146

Trust: 0.1

sources: VULHUB: VHN-57426 // VULMON: CVE-2012-4145 // BID: 54780 // JVNDB: JVNDB-2012-003481 // PACKETSTORM: 116866 // CNNVD: CNNVD-201208-023 // NVD: CVE-2012-4145

CREDITS

Reported by the vendor.

Trust: 0.3

sources: BID: 54780

SOURCES

db:VULHUBid:VHN-57426
db:VULMONid:CVE-2012-4145
db:BIDid:54780
db:JVNDBid:JVNDB-2012-003481
db:PACKETSTORMid:116866
db:CNNVDid:CNNVD-201208-023
db:NVDid:CVE-2012-4145

LAST UPDATE DATE

2024-11-23T21:55:56.576000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-57426date:2012-08-07T00:00:00
db:VULMONid:CVE-2012-4145date:2012-08-07T00:00:00
db:BIDid:54780date:2012-09-25T23:10:00
db:JVNDBid:JVNDB-2012-003481date:2012-08-08T00:00:00
db:CNNVDid:CNNVD-201208-023date:2012-08-07T00:00:00
db:NVDid:CVE-2012-4145date:2024-11-21T01:42:16.047

SOURCES RELEASE DATE

db:VULHUBid:VHN-57426date:2012-08-06T00:00:00
db:VULMONid:CVE-2012-4145date:2012-08-06T00:00:00
db:BIDid:54780date:2012-08-02T00:00:00
db:JVNDBid:JVNDB-2012-003481date:2012-08-08T00:00:00
db:PACKETSTORMid:116866date:2012-09-26T02:47:06
db:CNNVDid:CNNVD-201208-023date:2012-08-07T00:00:00
db:NVDid:CVE-2012-4145date:2012-08-06T16:55:07.243