Opera hit by buffer overflow glitch

Status
Not open for further replies.

Osiris

Golden Master
Messages
36,817
Location
Kentucky
Opera users are being urged to upgrade to a new version of the browser following the discovery of a potentially serious security bug.

The flaw means that vulnerable versions of the browsers will crash when visiting maliciously constructed web sites containing overly long (more than 256 bytes) URLs. Successful exploitation of this heap-based buffer overflow flaw creates a means for hackers to load malware onto the machines of visiting surfers.

The vulnerability affects versions 9.0 and 9.01 of Opera on Windows and Linux. Version 8.x of the browser software is not at risk to this particular flaw but rather than downgrading a better solution is to upgrade to version 9.02, as explained in Opera's advisory here. Opera described the flaw, discovered by security researcher firm iDefense, as "moderate".


http://www.theregister.com/2006/10/19/opera_security_bug/
 
Considering that Opera 9.02 has been out since 9/21 i dont see why people wouldnt have upgraded and avoided this flaw altogether. ;)
 
Makaveli213 said:
Considering that Opera 9.02 has been out since 9/21 i dont see why people wouldnt have upgraded and avoided this flaw altogether. ;)

There are people who refuse to move off of Windows 98 ;-)
 
Vulnerablility has been discovered quite a while after 9.02 was released. Nothing to worry about.
Firefox has a lot more vulnerabilities.
 
Microsoft responded Thursday to reports of the first exploit affecting Internet Explorer 7, which cropped up less than 24 hours after the browser's official launch. Christopher Budd from Microsoft's Security Response Center says the flaw lies not in IE7, but in an Outlook Express component.

This fact could explain why the problem first surfaced back in November 2003 and was found to affect IE6 last April. "While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express," Budd said. Microsoft notes it has received no reports of any attacks against customers, but is investigating the situation and may release a patch if necessary.


http://www.betanews.com/article/MS_IE7_Flaw_Really_in_Outlook_Express/1161290765
 
Status
Not open for further replies.
Back
Top Bottom