Category Archives: advisory

Carefully timed reloads, redirects, and navigation can spoof the address field – Opera Security Advisories

Severity Low Description The address field should always show the address of the page that is being displayed. Certain types of navigation, combined with reloads and redirects to a slowly-responding target site can cause the address field to show the target site’s address, while the attacking site is still being displayed. Opera’s Response Opera Software…

Printing issue can allow data leaks to other system users, or allow them to corrupt data – Opera Security Advisories

Severity Low Description When pages are printed by Opera, a temporary file is created, which contains the document to print. This document is not created with the correct permissions, allowing other users of the system to read its contents. When printed with certain popular printing frameworks, an additional temporary file is created by the framework…

History.state can leak the state data from cross domain pages – Opera Security Advisories

Severity Low Description When a site uses history.pushState and history.replaceState to add or replace history entries, it can also provide optional data, which may typically be used to restore the given state when the user navigates through their browser history. When pages with cross-domain frames use this functionality, Opera does not restrict that state data…