On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

October 22nd, 2008

On Opera patch day, a new zero-day flaw

Posted by Ryan Naraine @ 7:09 pm

Categories: Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Exploit code, Kernel-level Exploits, Passwords, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Opera Software, Web Browser, Zero-day Bug, Execution Attack, Web Browsers, Internet, Ryan Naraine

On Opera patch day, a new zero-day flawOn the same day Opera shipped a browser update with patches for three separate security vulnerabilities, hackers are openly discussion a new zero-day flaw that exposes Windows users to remote code execution attacks.

With Opera 9.61, the Norwegian browser maker corrects an issue where History Search could be used to reveal browser history (rated extremely severe);  a Fast Forward bug that allows cross-site scripting (highly severe); and an information disclosure flaw in news feeds (also highly severe).

But even as Opera users were scrambling to apply the latest patches, a public discussion on the Full Disclosure mailing list exposed a zero-day vulnerability that could lead to cross-site scripting and even remote code execution attacks.

The discussion began with this Roberto Suggi advisory on the History Search bug fixed in Opera 9.61 but quickly expanded to raise the possibility of code execution attacks.

Within hours, researcher Aviv Raff discovered a way to execute code from remote and released a harmless proof-of-concept exploit that launches the Windows calculator.

I can confirm that a separate exploit exists that launches harmful code remotely against fully patched versions of the Opera browser.

Until Opera can fix this new issue, users are strongly urged to consider a different browser or avoid clicking on links on untrusted Web pages.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 5 Talkback(s)
RE: On Opera patch day, a new zero-day flaw
This article gives incorrect information. The flaw as demostrated in the proof of concept was fixed in version 9.61. However, that flaw was present in 9.60. If you are using Opera 9.61, you are safe from this flaw. Editors should change this article accordingly.... (Read the rest)
Posted by: AssistantX Posted on: 10/26/08 You are currently: a Guest | | Terms of Use
Opera flaw  coopejx@... | 10/23/08
PoC doesn't work here  nacht@... | 10/23/08
There are other ways to protect oneself using Opera  nilotpal_c | 10/23/08
Not almost impossible, impossible  rpmyers1 | 10/23/08
RE: On Opera patch day, a new zero-day flaw  AssistantX | 10/26/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline