CVE-2008-4197
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 6.33% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- opera/opera browser
- Source
- cve@mitre.org
References
- http://bugs.gentoo.org/show_bug.cgi?id=235298Issue Tracking
- http://secunia.com/advisories/31549Broken Link, Vendor Advisory
- http://secunia.com/advisories/32538Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200811-01.xmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2008/09/19/2Mailing List
- http://www.openwall.com/lists/oss-security/2008/09/24/4Mailing List
- http://www.opera.com/docs/changelogs/freebsd/952/Broken Link
- http://www.opera.com/docs/changelogs/linux/952/Broken Link
- http://www.opera.com/docs/changelogs/solaris/952/Broken Link
- http://www.opera.com/docs/changelogs/windows/952/Broken Link
- http://www.opera.com/support/search/view/894/Broken Link
- http://www.securityfocus.com/bid/30768Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020720Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2416Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44552Third Party Advisory, VDB Entry
- http://bugs.gentoo.org/show_bug.cgi?id=235298Issue Tracking
- http://secunia.com/advisories/31549Broken Link, Vendor Advisory
- http://secunia.com/advisories/32538Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200811-01.xmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2008/09/19/2Mailing List
- http://www.openwall.com/lists/oss-security/2008/09/24/4Mailing List
- http://www.opera.com/docs/changelogs/freebsd/952/Broken Link
- http://www.opera.com/docs/changelogs/linux/952/Broken Link
- http://www.opera.com/docs/changelogs/solaris/952/Broken Link
- http://www.opera.com/docs/changelogs/windows/952/Broken Link
- http://www.opera.com/support/search/view/894/Broken Link
- http://www.securityfocus.com/bid/30768Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020720Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2416Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44552Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.