CVE-2012-4143
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog, a different vulnerability than CVE-2012-1924.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.opera.com/support/kb/view/1027/
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| linux-kernel | not-affected | | |
| macos | not-affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| opera | opera_browser | {"endIncluding":"12.00"} | |
| opera | opera_browser | 12.00 | |
| opera | opera_browser | 10.00 | |
| opera | opera_browser | 10.01 | |
| opera | opera_browser | 10.10 | |
| opera | opera_browser | 10.11 | |
| opera | opera_browser | 10.50 | |
| opera | opera_browser | 10.51 | |
| opera | opera_browser | 10.52 | |
| opera | opera_browser | 10.53 | |
| opera | opera_browser | 10.54 | |
| opera | opera_browser | 10.60 | |
| opera | opera_browser | 10.61 | |
| opera | opera_browser | 10.62 | |
| opera | opera_browser | 10.63 | |
| opera | opera_browser | 11.00 | |
| opera | opera_browser | 11.01 | |
| opera | opera_browser | 11.10 | |
| opera | opera_browser | 11.11 | |
| opera | opera_browser | 11.50 | |
| opera | opera_browser | 11.51 | |
| opera | opera_browser | 11.52 | |
| opera | opera_browser | 11.52.1100 | |
| opera | opera_browser | 11.60 | |
| opera | opera_browser | 11.61 | |
| opera | opera_browser | 11.62 | |
| opera | opera_browser | 11.64 | |
References
- http://www.opera.com/docs/changelogs/mac/1166/
- http://www.opera.com/docs/changelogs/mac/1201/
- http://www.opera.com/docs/changelogs/unix/1201/
- http://www.opera.com/docs/changelogs/windows/1201/
- http://www.opera.com/support/kb/view/1027/
- http://www.opera.com/docs/changelogs/mac/1166/
- http://www.opera.com/docs/changelogs/mac/1201/
- http://www.opera.com/docs/changelogs/unix/1201/
- http://www.opera.com/docs/changelogs/windows/1201/
- http://www.opera.com/support/kb/view/1027/
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.