CVE-2005-2405: Input Validation
Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2405?
CVE-2005-2405 is classified as a medium severity vulnerability due to the potential for arbitrary code execution.
How does CVE-2005-2405 allow for spoofing of file extensions?
CVE-2005-2405 allows attackers to spoof file extensions by exploiting how the Opera browser handles extended ASCII characters in the file download dialog.
Which version of Opera is affected by CVE-2005-2405?
CVE-2005-2405 specifically affects Opera version 8.01.
What type of attack is possible with CVE-2005-2405?
With CVE-2005-2405, attackers can trick users into executing arbitrary code by spoofing file extensions.
How can users protect themselves from CVE-2005-2405?
Users can protect themselves from CVE-2005-2405 by avoiding the use of Opera browser version 8.01 or by uninstalling the 'Arial Unicode MS' font.