On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

July 3rd, 2008

Opera patches serious code exection flaw

Posted by Ryan Naraine @ 11:11 am

Categories: Arbitrary Code Execution, Botnets, Browsers, Data theft, Exploit code, Firefox, Malware, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: Opera Software, Patch Management, Flaw, Security Statu, Security, Ryan Naraine

Opera patches serious code exection flawOpera Software has joined the list of browser vendors shipping fixes for serious remote code execution vulnerabilities.

The company’s new Opera 9.5.1 patches at least four security issues, the most serious being a flaw reported by Microsoft’s Billy Rios that could be used to execute arbitrary code.

Opera is withholding details on the high-risk flaw until a later date but, with Rios involved, it’s probably a safe bet this is a URI-handler flaw that could be exploited if a user is tricked into clicking on a rigged Web site.    Rios and my blogging collegue Nate McFeters have spent the better part of the last year warning about serious URI-handler security issues.

From the Opera 9.5.1 changelog:

  • Fixed an issue where <canvas> functions could reveal data from random places in memory, as reported by Philip Taylor. See our advisory.
  • Fixed an issue that could be used to execute arbitrary code, as reported by Billy Rios. Details will be disclosed at a later date.
  • Security status is now correctly set when navigating from HTTP to HTTPS.

The browser refresh also corrects an issue related to OCSP and CRLs that would lower security.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 1 Talkback(s)
URI/Protocol Handler Abuse  nmcfeters | 07/03/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc