Jump to content


- - - - -

7 Vulnerabilities, Some Severe, Patched In Opera 9.52


  • Please log in to reply
No replies to this topic

#1 Nvyseal

Nvyseal

    Chairman of the Board

  • Administrator
  • PipPipPipPipPipPip
  • 9,830 posts
  • Location:From the whatever it is, Pluto
  • Country:USA

Posted 21 August 2008 - 11:26 PM

images/news/internet.jpgOpera Software has updated its Web browser with fixes for at least seven documented security problems. Details on one more vulnerability, a cross-site scripting issue reported by Chris Weber, currently remains classified.

Opera warned that one of the seven flaws is rated “extremely severe” because of the risk of arbitrary code execution.

Improvements and fixes included in Opera 9.52 are:

1. (extremely severe): When Opera is registered as a handler for a given protocol, it can be started by external applications. In some cases, being started in this way can cause Opera to crash. To inject code, additional techniques will have to be employed. This bug affects Opera for Windows.

2. (highly severe): Scripts are able to change the addresses of framed pages that come from the same site. Due to a flaw in the way that Opera checks what frames can be changed, a site can change the address of frames on other sites inside any window that it has opened. This allows sites to open pages from other sites, and display misleading information on them.

3. (currently a secret): Fixed an issue that could allow cross-site scripting, as reported by Chris Weber of Casaba Security: details will be disclosed at a later date.

Read More





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users