vendor:
Opera for Linux
by:
Unknown
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Opera for Linux
Affected Version From: 7.54
Affected Version To: Unknown
Patch Exists: No
Related CWE:
CPE: a:opera:opera_linux:7.54
Platforms Tested: Linux
Unknown
Remote Command Execution vulnerability in Opera for Linux
Opera for Linux is susceptible to a remote command execution vulnerability. This issue is due to a default configuration setting in Opera that utilizes the KDE 'kfmclient' utility to open unknown content. Exploitation of this issue allows attacker-supplied commands to be executed in the context of the user running Opera.
Mitigation:
Update to a patched version of Opera. Avoid opening unknown content.