Avatar di Manolo De Agostini

a cura di Manolo De Agostini

E' stato rilasciato un fix per Opera 7.54 che risolve un problema di sicurezza del browser:

- Named frames or windows can be hi-jacked by malicious frames or windows.

- Periods in the file name and non-breaking spaces in the Content-Type header can make the save/open dialog misleading. A user may be convinced that an executable file is something else, for example a PDF document.

- Applets have access to sun.* packages

- Liveconnect: com.opera.EcmascriptObject constructor is accessible to Java

- Liveconnect reveals the path to the user's home directory. This can make other vulnerabilities easier to exploit.

Severity: Moderate/High

Opera 7.54 Windows with Java | Without Java