CVE-2012-3556: Input Validation
Opera before 11.65 does not properly restrict the opening of a pop-up window in response to the first click of a double-click action, which makes it easier for user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3556?
CVE-2012-3556 has been classified as a high severity vulnerability, allowing attackers to execute arbitrary code or conduct XSS attacks.
How do I fix CVE-2012-3556?
To mitigate CVE-2012-3556, upgrade the Opera browser to version 11.65 or later which contains the necessary patches.
What systems are affected by CVE-2012-3556?
CVE-2012-3556 affects multiple versions of the Opera browser, specifically those before version 11.65.
What type of attack can CVE-2012-3556 facilitate?
CVE-2012-3556 can facilitate cross-site scripting (XSS) attacks by allowing unauthorized pop-up window behavior.
Is there a workaround for CVE-2012-3556 if I cannot update my browser immediately?
As a temporary measure, users should avoid clicking on suspicious links or pop-ups until they can update their Opera browser.