First published: Wed Sep 21 2005(Updated: )
The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | =4.01 | |
Opera | =7.01 | |
Opera | =7.23 | |
Opera | =2.10 | |
Opera | =2.10-beta2 | |
Opera | =7.03 | |
Opera | =7.53 | |
Opera | =4.00-beta6 | |
Opera | =4.00-beta3 | |
Opera | =5.0-beta2 | |
Opera | =5.11 | |
Opera | =3.51 | |
Opera | =6.1 | |
Opera | =7.20 | |
Opera | =6.02 | |
Opera | =2.00 | |
Opera | =5.02 | |
Opera | =1.00 | |
Opera | =5.10 | |
Opera | =7.11-beta2 | |
Opera | =8.0 | |
Opera | =4.00 | |
Opera | =2.10-beta1 | |
Opera | =6.04 | |
Opera | =6.11 | |
Opera | =5.0-beta4 | |
Opera | =6.05 | |
Opera | =7.50-beta1 | |
Opera | =3.10 | |
Opera | =5.12 | |
Opera | =4.02 | |
Opera | =7.10 | |
Opera | =6.0-tp3 | |
Opera | =3.50 | |
Opera | =6.0-tp1 | |
Opera | =8.0-beta3 | |
Opera | =3.61 | |
Opera | =5.0-beta8 | |
Opera | =7.0-beta1_v2 | |
Opera | =3.00-beta | |
Opera | =5.0-beta5 | |
Opera | =4.00-beta5 | |
Opera | =7.50 | |
Opera | =7.02 | |
Opera | =7.21 | |
Opera | =6.0-tp2 | |
Opera | =5.0-beta7 | |
Opera | =7.20-beta7 | |
Opera | =7.54-update1 | |
Opera | =7.60 | |
Opera | =7.11 | |
Opera | =7.0-beta2 | |
Opera | =4.00-beta2 | |
Opera | =7.54 | |
Opera | =6.03 | |
Opera | =3.00 | |
Opera | =7.0-beta1 | |
Opera | =6.0-beta1 | |
Opera | =3.62 | |
Opera | =2.10-beta3 | |
Opera | =3.60 | |
Opera | =5.0 | |
Opera | =7.51 | |
Opera | =8.0-beta2 | |
Opera | =3.62-beta | |
Opera | =6.12 | |
Opera | =6.0-beta2 | |
Opera | =4.00-beta4 | |
Opera | =5.0-beta3 | |
Opera | =6.01 | |
Opera | =6.06 | |
Opera | =7.52 | |
Opera | =7.54-update2 | |
Opera | =3.21 | |
Opera | =5.0-beta6 | |
Opera | =8.01 | |
Opera | =6.1-beta1 | |
Opera | =2.12 | |
Opera | =8.0-beta1 | |
Opera | =6.0 | |
Opera | =7.22 | |
Opera | <=8.02 | |
Opera | =7.10-beta1 | |
Opera | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3006 is classified as a medium severity vulnerability due to potential scripting attacks.
To fix CVE-2005-3006, update to the Opera browser version 8.50 or later.
CVE-2005-3006 could allow attackers to execute arbitrary scripts on the user's browser by spoofing attachment filenames.
CVE-2005-3006 affects multiple versions of Opera prior to 8.50, including versions from 1.00 to 7.54.
A workaround for CVE-2005-3006 includes avoiding opening potentially malicious email attachments through the Opera browser until it can be updated.