CVE-2005-3750
7.5
CVSS Score
High
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Link copied!
Description
Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that another product provides in a command line argument when launching Opera.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Affected Software Configurations
- a opera opera_browser * * * * * * * *
Weaknesses (CWE)
- CWE-74
References & External Links
- http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0677.html
- http://secunia.com/advisories/16907
- http://secunia.com/advisories/18111
- http://secunia.com/secunia_research/2005-57/advisory/
- http://securityreason.com/securityalert/199
- http://securitytracker.com/id?1015253
- http://www.gentoo.org/security/en/glsa/glsa-200512-10.xml
- http://www.novell.com/linux/security/advisories/2005_28_sr.html
- http://www.opera.com/docs/changelogs/linux/851/
- http://www.osvdb.org/21003
- http://www.securityfocus.com/archive/1/417393/30/0/threaded
- http://www.securityfocus.com/bid/15521
- http://www.vupen.com/english/advisories/2005/2519
- http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0677.html
- http://secunia.com/advisories/16907
- http://secunia.com/advisories/18111
- http://secunia.com/secunia_research/2005-57/advisory/
- http://securityreason.com/securityalert/199
- http://securitytracker.com/id?1015253
- http://www.gentoo.org/security/en/glsa/glsa-200512-10.xml
- http://www.novell.com/linux/security/advisories/2005_28_sr.html
- http://www.opera.com/docs/changelogs/linux/851/
- http://www.osvdb.org/21003
- http://www.securityfocus.com/archive/1/417393/30/0/threaded
- http://www.securityfocus.com/bid/15521
- http://www.vupen.com/english/advisories/2005/2519
External Resources
CVE History Timeline
Nov 30, 2005 19:00
Initial Analysis
Oct 19, 2018 15:39
CVE Modified
Feb 28, 2022 16:23
Modified Analysis
May 14, 2024 01:32
CVE Modified
Nov 21, 2024 00:02
CVE Modified