First published: Wed Sep 02 2009(Updated: )
Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers to spoof URLs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | =7.23 | |
Opera | =9.02 | |
Opera | =7.53 | |
Opera | =8.50 | |
Opera | =9.51 | |
Opera | =8.53 | |
Opera | =9.12 | |
Opera | =8.0 | |
Opera | =8.54 | |
Opera | =8.02 | |
Opera | =9.20 | |
Opera | =9.21 | |
Opera | =8.51 | |
Opera | =9.64 | |
Opera | =7.60 | |
Opera | =7.54 | |
Opera | =9.22 | |
Opera | =9.01 | |
Opera | =9.0 | |
Opera | =9.10 | |
Opera | <=10.00 | |
Opera | =8.52 | |
Opera | =8.01 | |
Opera | =9.52 | |
Opera | =7.0 | |
Web Browser for Android | <=10.00 | |
Web Browser for Android | =7.0 | |
Web Browser for Android | =7.23 | |
Web Browser for Android | =7.53 | |
Web Browser for Android | =7.54 | |
Web Browser for Android | =7.60 | |
Web Browser for Android | =8.0 | |
Web Browser for Android | =8.01 | |
Web Browser for Android | =8.02 | |
Web Browser for Android | =8.50 | |
Web Browser for Android | =8.51 | |
Web Browser for Android | =8.52 | |
Web Browser for Android | =8.53 | |
Web Browser for Android | =8.54 | |
Web Browser for Android | =9.0 | |
Web Browser for Android | =9.01 | |
Web Browser for Android | =9.02 | |
Web Browser for Android | =9.10 | |
Web Browser for Android | =9.12 | |
Web Browser for Android | =9.20 | |
Web Browser for Android | =9.21 | |
Web Browser for Android | =9.22 | |
Web Browser for Android | =9.51 | |
Web Browser for Android | =9.52 | |
Web Browser for Android | =9.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3047 is considered a medium severity vulnerability due to its potential for URL spoofing.
To fix CVE-2009-3047, update your Opera browser to version 10.00 or later.
CVE-2009-3047 affects various versions of the Opera browser prior to version 10.00.
CVE-2009-3047 is a URL spoofing vulnerability caused by a failure to update the domain name in the address bar.
Yes, CVE-2009-3047 can be exploited remotely by attackers to spoof URLs during browsing.