1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Opera TLS Protocol Vulnerability

Report ID: SA201006416
Source: F-Secure
Date of Discovery: 09.03.2010
Criticality: Critical
Affects:
Opera 10.50 beta 2

Compromise From: From remote
Compromise Type: Unknown

Summary

Opera has reported a protocol vulnerability that impinge on connection security when the connection is renegotiated.

Detailed Description

A vulnerability has been reported in current versions of SSL and TLS protocols, involving a lack of cryptographic association between original set of security parameters and the one resulting after renegotiation. This condition may allow an attacker to inject data and instructions into the HTTPS connection, triggering unauthorized transactions made under the user's name.

Solution

Update to Opera 10.50 or later versions

Original Reference

Advisory: TLS protocol vulnerable to Man In The Middle attack (http://www.opera.com/support/kb/view/944/)