CVE-2003-1561: Infoleak
Published Dec 31, 2003
·Updated
Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
Affected Software
1 affected component
Opera Opera
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Jul 15, 2008
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1561?
The severity of CVE-2003-1561 is moderate due to potential information leakage.
2
How do I fix CVE-2003-1561?
To fix CVE-2003-1561, upgrade to a later version of Opera that addresses this vulnerability.
3
What information is exposed by CVE-2003-1561?
CVE-2003-1561 can expose potentially sensitive information contained in Referer headers when navigating from HTTPS to HTTP URLs.
4
Which versions of Opera are affected by CVE-2003-1561?
CVE-2003-1561 affects versions of Opera before 7.50.
5
Can attackers exploit CVE-2003-1561 easily?
Yes, attackers can exploit CVE-2003-1561 by analyzing Referer log data from requests made by affected Opera versions.