madison

Zero Day

Ryan Naraine and Dancho Danchev

'Extremely severe' flaw in Opera web browser

By | May 4, 2010, 10:10am PDT

Summary: An “extremely severe” security vulnerability in the Opera browser could put web surfers at risk of remote code execution attack

An “extremely severe” security vulnerability in the Opera browser could put web surfers at risk of remote code execution attacks, the software maker warned today.

The vulnerability, now patched with the new Opera 10.53, affects Opera for Windows and Mac.

Details on the flaw are scarce. In this advisory, Opera warns:

Multiple asynchronous calls to a script that modifies the document contents can cause Opera to reference an uninitialized value, which may lead to a crash. To inject code, additional techniques will have to be employed.

follow Ryan Naraine on twitter

Google has also been busy on the browser patch treadmill over the last few weeks, shipping two separate fixes for flaws in the Chrome browser.

The first Chrome update, shipped on April 20, addresses some very serious security defects:

  • High Risk — Type confusion error with forms. Credit: kuzzcc.
  • High Risk — HTTP request error leading to possible XSRF. Credit: Meder Kydyraliev, Google Security Team.
  • Medium Risk — Local file reference through developer tools. Credit: Robert Swiecki, Google Security Team; Tavis Ormandy, Google Security Team.
  • Medium Risk — Cross-site scripting in chrome://net-internals. Credit: Robert Swiecki, Google Security Team; Tavis Ormandy, Google Security Team.
  • High Risk — Cross-site scripting in chrome://downloads. Credit: Robert Swiecki, Google Security Team; Tavis Ormandy, Google Security Team.
  • Medium Risk — Pages might load with privileges of the New Tab page.
  • High Risk — Memory corruption in V8 bindings. Credit: kuzzcc; Google Chrome Security Team (SkyLined); Michal Zalewski, Google Security Team.

Then, on April 27, Google rushed out another Chrome update to fix the following:

  • High Risk — Cross-origin bypass in Google URL (GURL). Credit: Jordi Chancel.
  • High Risk — Memory corruption in HTML5 Media handling. Credit: David Bloom of Google Security Team.
  • High Risk — Memory corruption in font handling. Credit: wushi of team509.

The Google Chrome patches were automatically (and silently) shipped to the browser.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a security evangelist. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Talkback Most Recent of 89 Talkback(s)

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
Click Here
Click Here

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
Click Here