CVE-2010-2666: Critical severity web browser for android vulnerability
Opera before 10.54 on Windows and Mac OS X does not properly enforce permission requirements for widget filesystem access and directory selection, which allows user-assisted remote attackers to create or modify arbitrary files, and consequently execute arbitrary code, via widget File I/O operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2666?
CVE-2010-2666 is considered a medium severity vulnerability that can lead to arbitrary file creation or modification.
How do I fix CVE-2010-2666?
The recommended fix for CVE-2010-2666 is to upgrade to Opera version 10.54 or later, where the vulnerability has been addressed.
What does CVE-2010-2666 affect?
CVE-2010-2666 affects multiple versions of the Opera browser prior to 10.54 on both Windows and Mac OS X.
What type of vulnerability is CVE-2010-2666?
CVE-2010-2666 is a privilege escalation vulnerability stemming from improper permission enforcement for widget filesystem access.
Can CVE-2010-2666 be exploited remotely?
CVE-2010-2666 can be exploited by user-assisted remote attackers through specific widget File I/O operations.