Search

published date: December 31, 2004

CVE-2004-2491 : Race Condition Vulnerability

Description

A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.

Product(s):

  • Opera Browser
  • Opera Browser 1.00
  • Opera Browser 2.00
  • Opera Browser 2.10
  • Opera Browser 2.10b1

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-2491, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-2491 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?