First published: Wed Dec 07 2011(Updated: )
Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | <=11.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4690 has a medium severity rating due to the risk of information disclosure.
To mitigate CVE-2011-4690, users should upgrade to Opera version 11.61 or later.
CVE-2011-4690 may allow attackers to determine the existence of documents stored in the browser cache.
Opera versions 11.60 and earlier are affected by CVE-2011-4690.
CVE-2011-4690 exploits the Same Origin Policy by allowing data capture regarding policy violations during IFRAME loading.