First published: Tue Dec 31 2002(Updated: )
Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | =6.0.3 | |
Squid Web Proxy Cache | =2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2414 is categorized as a denial of service vulnerability that may crash the Opera browser when certain conditions are met.
CVE-2002-2414 affects Opera version 6.0.3 and Squid version 2.4.
To mitigate CVE-2002-2414, upgrade to a later version of Opera or Squid that addresses this vulnerability.
Yes, CVE-2002-2414 can be exploited remotely by attackers to trigger a denial of service.
No, CVE-2002-2414 specifically involves issues with non-global certificate authority certificates, so using a global CA does not mitigate the vulnerability.