CVE-2004-0473 Information

Description

Argument injection vulnerability in Opera before 7.50 does not properly filter -\ characters that begin a hostname in a telnet URI which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the -f\ option on Windows XP or (2) the -n\ option on Linux.

Reference

http://security.gentoo.org/glsa/glsa-200405-19.xml http://securitytracker.com/id?1010142 http://www.idefense.com/application/poi/display?id=104&type=vulnerabilities http://www.opera.com/linux/changelogs/750/index.dml http://www.securityfocus.com/bid/10341 https://exchange.xforce.ibmcloud.com/vulnerabilities/16139

Share on: