CVE-2008-4197
Last modified
CVE-2008-4197 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.. EPSS estimates a 6.33% chance of exploitation in the next 30 days.
Description
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | < 9.52 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=235298Issue Tracking
- http://secunia.com/advisories/31549Broken Link, Vendor Advisory
- http://secunia.com/advisories/32538Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200811-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/30768Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020720Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44552Third Party Advisory, VDB Entry
- http://bugs.gentoo.org/show_bug.cgi?id=235298Issue Tracking
- http://secunia.com/advisories/31549Broken Link, Vendor Advisory
- http://secunia.com/advisories/32538Broken Link, Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200811-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/30768Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020720Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44552Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4197?
How severe is CVE-2008-4197?
How do I fix CVE-2008-4197?
Are you affected by CVE-2008-4197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
