CVE-2011-4690: Medium severity web browser for android vulnerability
Published Dec 7, 2011
·Updated
Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.
Affected Software
1 affected component
opera Opera Browser<=11.60
Event History
Dec 7, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4690?
CVE-2011-4690 has a medium severity rating due to the risk of information disclosure.
2
How do I fix CVE-2011-4690?
To mitigate CVE-2011-4690, users should upgrade to Opera version 11.61 or later.
3
What are the potential impacts of CVE-2011-4690?
CVE-2011-4690 may allow attackers to determine the existence of documents stored in the browser cache.
4
Which versions of Opera are affected by CVE-2011-4690?
Opera versions 11.60 and earlier are affected by CVE-2011-4690.
5
How does CVE-2011-4690 exploit the Same Origin Policy?
CVE-2011-4690 exploits the Same Origin Policy by allowing data capture regarding policy violations during IFRAME loading.