First published: Wed Feb 11 2004(Updated: )
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | >=7.0<=7.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2083 has a medium severity rating due to the potential for remote exploitation.
To fix CVE-2004-2083, it is recommended to upgrade to a newer version of the Opera Web Browser that is not affected.
CVE-2004-2083 affects Opera Web Browser versions 7.0 through 7.23.
CVE-2004-2083 exploits a vulnerability in handling file names, leading to potential file download extension spoofing.
Users of Opera Web Browser versions 7.0 to 7.23 may be tricked into executing malicious files.