On CBS MoneyWatch: Reggie Bush vs. racehorse: Who's faster?
BNET Business Network:
BNET
TechRepublic
ZDNet

October 28th, 2009

Opera browser dinged by code execution flaw

Posted by Ryan Naraine @ 9:18 am

Categories: Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Firefox, Malware, Mozilla, Open source, Passwords, Patch Watch

Tags: Opera Browser, Flaw, Opera Software ASA, Web Browser, Domain Names, Web Browsers, Patches, Security, Internet, Ryan Naraine

Mozilla isn’t the only alternative browser maker struggling with serious security problems.

On the same day Mozilla shipped a Firefox update to fix multiple critical vulnerabilities, Opera dropped a major patch to fix three documented flaws, including a memory corruption issue that exposes users to code execution attacks.

[ SEE: Firefox hit by multiple drive-by download flaws ]

Here’s the skinny:

  • Advisory #1: Specially crafted domain names can cause a memory corruption in Opera, which may lead to a crash. Successful exploitation can lead to execution of arbitrary code.  Rated “extremely severe.”
  • Advisory #2: Opera may allow scripts to run on the feed subscription page, thereby gaining access to the feeds object. This can be used for automatic subscription of feeds, or reading other feeds.  (Less severe)
  • Advisory #3:  In some cases, a Web font intended to be used for page content could be incorrectly used by Opera to render parts of the user interface, including the address field. This can be used by a malicious site to display a false domain name in the address field. (Less severe)

Patches for these flaws area available in Opera 10.01.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 12 Talkback(s)
Ahhh! Stop the world...
Opera has another vulnerability! (Read the rest)
Posted by: Agnostic_OS Posted on: 10/31/09 You are currently: a Guest | | Terms of Use
Just think.  Erroneous | 10/28/09
Just think.  AzuMao | 10/28/09
Opera is great.  CounterEthicsCommissioner-23034636492738337469105860790963 | 10/28/09
So what about 8 users worldwide at risk?  Johnny Vegas | 10/28/09
I make 9  People | 10/28/09
I'm #10  [deXter] | 10/30/09
I love Opera...  silversidhe | 10/28/09
Is this note worth reading?  hectormacias | 10/28/09
no  ljenux-23043766007667558234416105604265 | 10/29/09
Not the only browser  pizzaman7 | 10/30/09
Never Ending Browser Vulnerabilities  eiverson@... | 10/30/09
Ahhh! Stop the world...  Agnostic_OS | 10/31/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here