First published: Wed Jul 07 2010(Updated: )
Opera before 10.54 on Windows and Mac OS X does not properly enforce permission requirements for widget filesystem access and directory selection, which allows user-assisted remote attackers to create or modify arbitrary files, and consequently execute arbitrary code, via widget File I/O operations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | <=10.53 | |
Opera | =5.0 | |
Opera | =5.0-beta2 | |
Opera | =5.0-beta3 | |
Opera | =5.0-beta4 | |
Opera | =5.0-beta5 | |
Opera | =5.0-beta6 | |
Opera | =5.0-beta7 | |
Opera | =5.0-beta8 | |
Opera | =5.02 | |
Opera | =5.10 | |
Opera | =5.11 | |
Opera | =5.12 | |
Opera | =6.0 | |
Opera | =6.0-beta1 | |
Opera | =6.0-beta2 | |
Opera | =6.0-tp1 | |
Opera | =6.0-tp2 | |
Opera | =6.0-tp3 | |
Opera | =6.01 | |
Opera | =6.02 | |
Opera | =6.03 | |
Opera | =6.04 | |
Opera | =6.05 | |
Opera | =6.06 | |
Opera | =7.0 | |
Opera | =7.0-beta1 | |
Opera | =7.0-beta1_v2 | |
Opera | =7.0-beta2 | |
Opera | =7.01 | |
Opera | =7.02 | |
Opera | =7.03 | |
Opera | =7.10 | |
Opera | =7.10-beta1 | |
Opera | =7.11 | |
Opera | =7.11-beta2 | |
Opera | =7.20 | |
Opera | =7.20-beta7 | |
Opera | =7.21 | |
Opera | =7.22 | |
Opera | =7.23 | |
Opera | =7.50 | |
Opera | =7.50-beta1 | |
Opera | =7.51 | |
Opera | =7.52 | |
Opera | =7.53 | |
Opera | =7.54 | |
Opera | =7.54-update1 | |
Opera | =7.54-update2 | |
Opera | =7.60 | |
Opera | =8.0 | |
Opera | =8.0-beta1 | |
Opera | =8.0-beta2 | |
Opera | =8.0-beta3 | |
Opera | =8.01 | |
Opera | =8.02 | |
Opera | =8.50 | |
Opera | =8.51 | |
Opera | =8.52 | |
Opera | =8.53 | |
Opera | =8.54 | |
Opera | =9.0 | |
Opera | =9.0-beta1 | |
Opera | =9.0-beta2 | |
Opera | =9.01 | |
Opera | =9.02 | |
Opera | =9.10 | |
Opera | =9.12 | |
Opera | =9.20 | |
Opera | =9.20-beta1 | |
Opera | =9.21 | |
Opera | =9.22 | |
Opera | =9.23 | |
Opera | =9.24 | |
Opera | =9.25 | |
Opera | =9.26 | |
Opera | =9.27 | |
Opera | =9.50 | |
Opera | =9.50-beta1 | |
Opera | =9.50-beta2 | |
Opera | =9.51 | |
Opera | =9.52 | |
Opera | =9.60 | |
Opera | =9.60-beta1 | |
Opera | =9.61 | |
Opera | =9.62 | |
Opera | =9.63 | |
Opera | =9.64 | |
Opera | =10.00 | |
Opera | =10.00-beta1 | |
Opera | =10.00-beta2 | |
Opera | =10.00-beta3 | |
Opera | =10.01 | |
Opera | =10.10 | |
Opera | =10.10-beta1 | |
Opera | =10.50 | |
Opera | =10.50-beta1 | |
Opera | =10.51 | |
Opera | =10.52 | |
Microsoft Windows | ||
Opera | =6.0-beta3 | |
Opera | =10.52-beta1 | |
Opera | =10.52-beta2 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2666 is considered a medium severity vulnerability that can lead to arbitrary file creation or modification.
The recommended fix for CVE-2010-2666 is to upgrade to Opera version 10.54 or later, where the vulnerability has been addressed.
CVE-2010-2666 affects multiple versions of the Opera browser prior to 10.54 on both Windows and Mac OS X.
CVE-2010-2666 is a privilege escalation vulnerability stemming from improper permission enforcement for widget filesystem access.
CVE-2010-2666 can be exploited by user-assisted remote attackers through specific widget File I/O operations.