Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-07-28T04:00:00

Updated: 2024-08-07T22:22:49.133Z

Reserved: 2005-07-28T00:00:00

Link: CVE-2005-2405

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2005-08-01T04:00:00.000

Modified: 2022-02-28T16:31:07.417

Link: CVE-2005-2405

cve-icon Redhat

No data.