First published: Thu Feb 06 2014(Updated: )
The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | <=17.00 | |
Opera | =1.00 | |
Opera | =10.00 | |
Opera | =10.00-alpha | |
Opera | =10.00-beta1 | |
Opera | =10.00-beta2 | |
Opera | =10.00-beta3 | |
Opera | =10.01 | |
Opera | =10.10 | |
Opera | =10.10-beta1 | |
Opera | =10.11 | |
Opera | =10.20-alpha | |
Opera | =10.50 | |
Opera | =10.50-beta1 | |
Opera | =10.50-beta2 | |
Opera | =10.51 | |
Opera | =10.52 | |
Opera | =10.52-beta1 | |
Opera | =10.52-beta2 | |
Opera | =10.53 | |
Opera | =10.53-b | |
Opera | =10.53-beta1 | |
Opera | =10.54 | |
Opera | =10.60 | |
Opera | =10.60-alpha | |
Opera | =10.60-beta1 | |
Opera | =10.61 | |
Opera | =10.62 | |
Opera | =10.63 | |
Opera | =11.00 | |
Opera | =11.00-beta | |
Opera | =11.01 | |
Opera | =11.10 | |
Opera | =11.10-beta | |
Opera | =11.11 | |
Opera | =11.50 | |
Opera | =11.50-beta | |
Opera | =11.51 | |
Opera | =11.52 | |
Opera | =11.52.1100 | |
Opera | =11.60 | |
Opera | =11.60-beta | |
Opera | =11.61 | |
Opera | =11.62 | |
Opera | =11.64 | |
Opera | =11.65 | |
Opera | =11.66 | |
Opera | =11.67 | |
Opera | =12.00 | |
Opera | =12.00-beta | |
Opera | =12.01 | |
Opera | =12.02 | |
Opera | =12.10 | |
Opera | =12.10-beta | |
Opera | =12.11 | |
Opera | =12.12 | |
Opera | =12.13 | |
Opera | =12.14 | |
Opera | =12.15 | |
Opera | =15.00 | |
Opera | =15.00-next | |
Opera | =16.00 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0815 is considered a moderate severity vulnerability due to the potential for local file disclosure.
To fix CVE-2014-0815, update the Opera browser to version 18 or later to eliminate the vulnerability.
CVE-2014-0815 allows attackers to read local files, including stored cookies, on affected devices.
CVE-2014-0815 affects Opera versions before 18 on Android, including all versions up to and including 17.00.
CVE-2014-0815 is specifically relevant to the Opera browser on Android devices.