CVE-2008-4197
Publication date 27 September 2008
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| opera | 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release | |
| 7.10 gutsy | Not in release | |
| 7.04 feisty | Ignored end of life, was needed | |
| 6.06 LTS dapper | Not in release |
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | High |
| Availability impact | High |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |