- Document opera -- multiple vulnerabilities

Reviewed by:	remko
This commit is contained in:
Martin Wilke 2007-10-25 18:34:32 +00:00
parent 3831f578ff
commit b7852ea261
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=202013

View file

@ -34,6 +34,47 @@ Note: Please add new entries to the beginning of this file.
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
<vuln vid="44224e08-8306-11dc-9283-0016179b2dd5">
<topic>opera -- multiple vulnerabilities</topic>
<affects>
<package>
<name>opera</name>
<name>opera-devel</name>
<name>linux-opera</name>
<range><lt>9.24</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>An advisory from Opera reports:</p>
<blockquote cite="http://www.opera.com/support/search/view/866/">
<p>If a user has configured Opera to use an external newsgroup
client or e-mail application, specially crafted Web pages can
cause Opera to run that application incorrectly. In some cases
this can lead to execution of arbitrary code.</p>
</blockquote>
<blockquote cite="http://www.opera.com/support/search/view/867/">
<p>When accesing frames from different Web sites, specially crafted
scripts can bypass the same-origin policy, and overwrite functions
from those frames. If scripts on the page then run those functions,
this can cause the script of the attacker's choice to run in the
context of the target Web site.</p>
</blockquote>
</body>
</description>
<references>
<cvename>CVE-2007-5540</cvename>
<cvename>CVE-2007-5541</cvename>
<url>http://www.opera.com/support/search/view/866/</url>
<url>http://www.opera.com/support/search/view/867/</url>
<url>http://secunia.com/advisories/27277/</url>
</references>
<dates>
<discovery>2007-10-17</discovery>
<entry>2007-10-25</entry>
</dates>
</vuln>
<vuln vid="9c00d446-8208-11dc-9283-0016179b2dd5">
<topic>drupal --- multiple vulnerabilities</topic>
<affects>