CVE-2009-1234: Input Validation
Published Apr 2, 2009
·Updated
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected.
Affected Software
2 affected components
opera Opera Browser=9.64
opera Opera Browser=9.52
Event History
Apr 2, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-1234?
The severity of CVE-2009-1234 is rated as medium with a score of 4.3.
2
What type of attack does CVE-2009-1234 facilitate?
CVE-2009-1234 allows remote attackers to cause a denial of service by crashing the Opera browser.
3
Which versions of the Opera browser are affected by CVE-2009-1234?
CVE-2009-1234 affects Opera versions 9.64 and 9.52.
4
How do I mitigate the risks associated with CVE-2009-1234?
To mitigate risks from CVE-2009-1234, it is advisable to upgrade to a newer, patched version of the Opera browser.
5
What is the nature of the vulnerability in CVE-2009-1234?
CVE-2009-1234 is an input validation vulnerability that allows for Denial of Service attacks through improperly formatted XML documents.