Vulnerability Description
Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera Browser | < 10.00 |
Related Weaknesses (CWE)
References
- http://www.opera.com/docs/changelogs/freebsd/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/linux/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/mac/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/solaris/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/windows/1000/Broken LinkVendor Advisory
- http://www.opera.com/support/kb/view/929/Broken LinkVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Broken Link
- http://www.opera.com/docs/changelogs/freebsd/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/linux/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/mac/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/solaris/1000/Broken LinkVendor Advisory
- http://www.opera.com/docs/changelogs/windows/1000/Broken LinkVendor Advisory
- http://www.opera.com/support/kb/view/929/Broken LinkVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Broken Link
FAQ
What is CVE-2009-3046?
CVE-2009-3046 is a vulnerability with a CVSS score of 7.5 (HIGH). Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certifica...
How severe is CVE-2009-3046?
CVE-2009-3046 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3046?
Check the references section above for vendor advisories and patch information. Affected products include: Opera Opera Browser.