CVE-2012-1926: Infoleak
Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1926?
CVE-2012-1926 has been rated as having a medium severity due to the potential for attackers to bypass the Same Origin Policy.
How do I fix CVE-2012-1926?
To fix CVE-2012-1926, users should upgrade to Opera version 11.62 or later.
What can an attacker do with CVE-2012-1926?
An attacker can exploit CVE-2012-1926 to gain unauthorized access to history.state information through cross-domain frames.
Which versions of Opera are affected by CVE-2012-1926?
CVE-2012-1926 affects Opera versions prior to 11.62 and several earlier versions including 5.x, 6.x, 7.x, up to 11.61.
Is CVE-2012-1926 exploit mitigated in newer versions?
Yes, CVE-2012-1926 is mitigated in Opera version 11.62 and later, which addresses the vulnerability.