Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows >> Opera < 9.10 Multiple Vulnerabilities


Vulnerability Assessment Details

Opera < 9.10 Multiple Vulnerabilities

Vulnerability Assessment Summary
Checks version number of Opera

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote host contains a web browser which is susceptible to
multiple issues.

Description :

The version of Opera installed on the remote host reportedly contains
a heap overflow vulnerability that can be triggered when processing
the DHT marker in a specially-crafted JPEG image to crash the browser
or possibly permit execution of arbitrary code on the affected host.

In addition, another flaw in Opera's createSVGTransformFromMatrix
object typecasting may lead to a browser crash or arbitrary code
execution if support for Javascript is enabled.

See also :

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457
http://www.securityfocus.com/archive/1/456053
http://www.securityfocus.com/archive/1/456066
http://www.opera.com/support/search/supsearch.dml?index=851
http://www.opera.com/support/search/supsearch.dml?index=852

Solution :

Upgrade to Opera version 9.10 or later.

Network Security Threat Level:

High / CVSS Base Score : 8.0
(AV:R/AC:H/Au:NR/C:C/I:C/A:C/B:N)

Networks Security ID: 21882

Vulnerability Assessment Copyright: This script is Copyright (C) 2007 Tenable Network Security

Cables, Connectors

vintage Dec/Digital M7946 QBus RXV11 Floppy Disk Controller
$59.95
vintage Dec/Digital M7946 QBus RXV11 Floppy Disk Controller picturevintage Dec/Digital M7940 QBus Serial Line Unit
$44.95
vintage Dec/Digital M7940 QBus Serial Line Unit pictureDEC Alpha 21264 500XCN Vintage 1996 Server CPU Card
$50.0
DEC Alpha 21264 500XCN Vintage 1996 Server CPU Card picturedigital DECpc LPx 466d2 486 DX DX2 66 PC DOS Windows 3.1 Vintage DEC Computer
$300.0
digital DECpc LPx 466d2 486 DX DX2 66 PC DOS Windows 3.1 Vintage DEC Computer picture


Discussions

No Discussions have been posted on this vulnerability.