Feed links can link to local files – Opera Security Advisories


Less Severe

Problem Description

As a security precaution, Opera does not allow Web pages to link to files on the user’s local disk. However, a flaw exists that allows Web pages to link to feed source files on the user’s computer. Suitable detection of JavaScript events and appropriate manipulation can unreliably allow a script to detect the difference between successful and unsuccessful subscriptions to these files, to allow it to discover if the file exists or not. In most cases the attempt will fail.


Opera’s Response

Opera Software has released Opera 9.52, where this issue has been fixed.