Executive Summary

Informations
Name CVE-2009-2070 First vendor Publication 2009-06-15
Vendor Cve Last vendor Modification 2012-06-07

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2070

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-287 Improper Authentication

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

OpenVAS Exploits

Date Description
2012-08-10 Name : Gentoo Security Advisory GLSA 201206-03 (Opera)
File : nvt/glsa_201206_03.nasl
2009-09-21 Name : SuSE Security Summary SUSE-SR:2009:015
File : nvt/suse_sr_2009_015.nasl
2009-06-17 Name : Opera Web Script Execution Vulnerabilities - June09 (Linux)
File : nvt/secpod_opera_web_script_exec_vuln_jun09_lin.nasl
2009-06-17 Name : Opera Web Script Execution Vulnerabilities - June09 (Win)
File : nvt/secpod_opera_web_script_exec_vuln_jun09_win.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
56487 Opera Proxy Server CONNECT Response Cached Certificate Use MiTM HTTPS Site Sp...

Nessus® Vulnerability Scanner

Date Description
2012-06-21 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201206-03.nasl - Type : ACT_GATHER_INFO
2009-10-06 Name : The remote openSUSE host is missing a security update.
File : suse_opera-6473.nasl - Type : ACT_GATHER_INFO
2009-09-03 Name : The remote openSUSE host is missing a security update.
File : suse_11_0_opera-090902.nasl - Type : ACT_GATHER_INFO
2009-09-03 Name : The remote openSUSE host is missing a security update.
File : suse_11_1_opera-090901.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/35411
MISC http://research.microsoft.com/apps/pubs/default.aspx?id=79323
http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
Date Informations
2021-05-04 12:09:42
  • Multiple Updates
2021-04-22 01:10:03
  • Multiple Updates
2020-05-23 00:23:55
  • Multiple Updates
2016-04-26 18:54:03
  • Multiple Updates
2014-02-17 10:50:31
  • Multiple Updates
2013-05-10 23:52:32
  • Multiple Updates