CVE-2013-1638: Code Injection
Published Feb 8, 2013
·Updated
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
Affected Software
8 affected components
opera Opera Browser<=12.12
opera Opera Browser=12.00
opera Opera Browser=12.00-beta
opera Opera Browser=12.01
opera Opera Browser=12.02
opera Opera Browser=12.10
opera Opera Browser=12.10-beta
opera Opera Browser=12.11
Event History
Feb 8, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1638?
CVE-2013-1638 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2013-1638?
To mitigate CVE-2013-1638, update the Opera browser to version 12.13 or later.
3
Which versions of Opera are affected by CVE-2013-1638?
CVE-2013-1638 affects Opera versions prior to 12.13, including 12.00, 12.01, 12.02, 12.10, 12.11, and 12.12.
4
Is it possible to exploit CVE-2013-1638 remotely?
Yes, attackers can exploit CVE-2013-1638 remotely through specially crafted SVG documents.
5
What kind of attacks can CVE-2013-1638 enable?
CVE-2013-1638 can enable attackers to execute arbitrary code on a vulnerable system.