Advertisement
Promo

Security threats Toolkit

Opera patches seven security flaws

Colin Barker ZDNet.co.uk

Published: 17 Dec 2008 14:44 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Opera has issued an update to its web-browser software to fix seven vulnerabilities, two of them rated by the company as 'extremely severe'.

Opera 9.63, released for download on Tuesday, only applies to Microsoft Windows PCs and is described by the company as a 'recommended security upgrade'.

One of the two most serious flaws tackled by the update could allow an attacker to manipulate text input to cause a buffer overflow, and then execute arbitrary code, meaning that the attacker could take remote control of the computer. The second critical flaw relates to HTML parsing, and means that certain HTML could cause unexpected changes that trigger a crash. An intruder would have to use additional techniques to inject code, Opera said in an advisory.

Three other issues are rated 'highly severe'. Lost hostnames in file: URLs could be exploited to cause a buffer overflow, which could be used to execute arbitrary code. However, people would need to be tricked into manually opening a malicious URL for an attack to be launched, Opera said.

The second 'highly severe' vulnerability affects previews of news feeds, and could let an intruder see the contents of a user's feeds. The third vulnerability relates to incorrect handling of escaped content in built-in XSLT templates.

The remaining issues do not carry a severity rating, and relate to a problem that could reveal random data, and an issue with the embedding of SVG images.

Opera users can find more details on the security issues in the release notes for the update.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters