First published: Fri Dec 31 2004(Updated: )
Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking Open via a request for a different mouse or keyboard action very shortly before the Open dialog appears. NOTE: this is a different issue than CVE-2005-2407.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | ||
Mozilla Firefox |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2659 is classified as a medium severity vulnerability due to its reliance on user interaction.
To mitigate CVE-2004-2659, ensure that your browser is updated to the latest version provided by the vendor.
CVE-2004-2659 affects the Opera browser and Mozilla applications.
CVE-2004-2659 represents a user-assisted remote attack exploiting a race condition.
Exploiting CVE-2004-2659 could allow attackers to trick users into executing potentially malicious files.