Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows >> Opera < 9.10 Multiple Vulnerabilities


Vulnerability Assessment Details

Opera < 9.10 Multiple Vulnerabilities

Vulnerability Assessment Summary
Checks version number of Opera

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote host contains a web browser which is susceptible to
multiple issues.

Description :

The version of Opera installed on the remote host reportedly contains
a heap overflow vulnerability that can be triggered when processing
the DHT marker in a specially-crafted JPEG image to crash the browser
or possibly permit execution of arbitrary code on the affected host.

In addition, another flaw in Opera's createSVGTransformFromMatrix
object typecasting may lead to a browser crash or arbitrary code
execution if support for Javascript is enabled.

See also :

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=458
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=457
http://www.securityfocus.com/archive/1/456053
http://www.securityfocus.com/archive/1/456066
http://www.opera.com/support/search/supsearch.dml?index=851
http://www.opera.com/support/search/supsearch.dml?index=852

Solution :

Upgrade to Opera version 9.10 or later.

Network Security Threat Level:

High / CVSS Base Score : 8.0
(AV:R/AC:H/Au:NR/C:C/I:C/A:C/B:N)

Networks Security ID: 21882

Vulnerability Assessment Copyright: This script is Copyright (C) 2007 Tenable Network Security

Cables, Connectors

Dell R630 6-Core Server 1x E5-2643 v3 3.4GHz 16GB H730 8x 300GB 15K iDRAC Rails
$3117.0
Dell R630 6-Core Server 1x E5-2643 v3 3.4GHz 16GB H730 8x 300GB 15K iDRAC Rails pictureDell R630 12-Core Server 1x E5-2690 v3 2.6GHz 48GB H730 8x 300GB 15K iDRAC Rails
$4457.0
Dell R630 12-Core Server 1x E5-2690 v3 2.6GHz 48GB H730 8x 300GB 15K iDRAC Rails pictureDell R630 16-Core Server 2x E5-2640 v3 2.6GHz 64GB H730 8x 600GB 15K iDRAC Rails
$5306.0
Dell R630 16-Core Server 2x E5-2640 v3 2.6GHz 64GB H730 8x 600GB 15K iDRAC Rails pictureDell R630 12-Core Server 1x E5-2690 v3 2.6GHz 48GB H730 iDRAC Rails RPS
$3859.0
Dell R630 12-Core Server 1x E5-2690 v3 2.6GHz 48GB H730 iDRAC Rails RPS picture


Discussions

No Discussions have been posted on this vulnerability.