Results 1 to 9 of 9
Thread: Zero day bugs for Opera too
- 03-07-2010 #1
Zero day bugs for Opera too
http://www.theregister.co.uk/2010/03...vulnerability/
http://secunia.com/advisories/38820/
http://www.vupen.com/english/advisories/2010/0529Criticality level Highly critical
Impact System access
Where From remote
Description
Marcin Ressel has discovered a vulnerability in Opera, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an error when processing HTTP responses having a malformed "Content-Length" header. This can be exploited to cause a heap-based buffer overflow via an overly large 64-bit "Content-Length" value, having the higher 32-bit part negative.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is confirmed in version 10.50 for Windows. Other versions may also be affected.
Solution
Do not browse untrusted websites or follow untrusted links.
- 03-07-2010 #2
This is actually a compliment in a twisted way.
It's a sign of success. Welcome to the big time Opera. People are now trying to exploit your creation and are announcing it to the world. Welcome, welcome...
Last edited by evilfantasy; 03-07-2010 at 09:35 AM.
- 03-07-2010 #3
- 03-07-2010 #4*nix Technical Support
Achievements:




Awards:
- Join Date
- Jan 2009
- Location
- /home/hellnoire
- Posts
- 10,231
- Liked
- 293 times
Well, join the club, because now with a zero day bug, it's big enough to target lol.
pacman -Syyu life not found in sync db
- 03-07-2010 #5
they even deny it
(like Mozilla) follow thead here if you're interested
Last edited by noaccount; 03-07-2010 at 05:03 PM.
- 03-08-2010 #6
- 03-08-2010 #7*nix Technical Support
Achievements:




Awards:
- Join Date
- Jan 2009
- Location
- /home/hellnoire
- Posts
- 10,231
- Liked
- 293 times
Avant has the same flaws IE has... as it's IE based. So no, that won't work either, I'm afraid.
- 03-09-2010 #8http://www.computerworld.com/s/artic...al_browser_bugOpera confirms critical browser bug
Working on patch for Windows vulnerability
- 03-17-2010 #9
Opera rocks. I've been using this for 3 yrs and love all the features. Recent, updates are worse. I hope that Opera makes some good changes. Their Opera Unite is awesome and hope the browser stays with its promise.
My right to post information is protected under the constitutional rights for freedom.
Similar Threads
-
Christmas at Opera Labs: 64-bit Opera, and out-of-process plug-ins
By A Guy in forum Latest ReleasesReplies: 5Last Post: 12-18-2011, 05:58 PM -
Opera@USB 11.51 - portable Opera for USB / flash drive
By solin in forum Latest ReleasesReplies: 0Last Post: 09-08-2011, 02:57 PM -
[Opera Beta Version Update] Opera 11.10 “Barracuda” Build 2064 Released
By doubeLL in forum Latest ReleasesReplies: 5Last Post: 03-29-2011, 02:49 PM -
Opera Content Writing Uninitialised Memory Vulnerability - Opera 10.53 RC1
By leofelix in forum Security BulletinReplies: 0Last Post: 04-29-2010, 08:46 AM -
For Opera 9.5 Users: How to add more speed dials in opera 9.5
By bahirzaheri8 in forum General ForumReplies: 4Last Post: 06-16-2008, 01:41 AM


LinkBack URL
About LinkBacks





Reply With Quote



