First published: Fri Apr 21 2017(Updated: )
Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | =36.0 | |
Opera Mini | =13.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4075 has a medium severity rating because it allows remote attackers to spoof URLs in the Opera Mini and Opera Stable browsers.
To fix CVE-2016-4075, users should update their Opera Mini to version 14.0 or later and Opera Stable to version 37.0 or later.
CVE-2016-4075 affects Opera Mini version 13.00 and Opera Stable version 36.0.
Exploitation of CVE-2016-4075 allows attackers to spoof the displayed URL, which can mislead users into believing they are on a legitimate site.
While updating is the recommended action, users can avoid potential spoofing by not interacting with untrusted links until a patch has been applied.