ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Opera browser dinged by code execution flaw

By | October 28, 2009, 9:18am PDT

Summary: Opera releases version 10.01 to fix three documented flaws, including a memory corruption issue that exposes users to code execution attacks.

Mozilla isn’t the only alternative browser maker struggling with serious security problems.

On the same day Mozilla shipped a Firefox update to fix multiple critical vulnerabilities, Opera dropped a major patch to fix three documented flaws, including a memory corruption issue that exposes users to code execution attacks.

[ SEE: Firefox hit by multiple drive-by download flaws ]

Here’s the skinny:

  • Advisory #1: Specially crafted domain names can cause a memory corruption in Opera, which may lead to a crash. Successful exploitation can lead to execution of arbitrary code.  Rated “extremely severe.”
  • Advisory #2: Opera may allow scripts to run on the feed subscription page, thereby gaining access to the feeds object. This can be used for automatic subscription of feeds, or reading other feeds.  (Less severe)
  • Advisory #3:  In some cases, a Web font intended to be used for page content could be incorrectly used by Opera to render parts of the user interface, including the address field. This can be used by a malicious site to display a false domain name in the address field. (Less severe)

Patches for these flaws area available in Opera 10.01.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
13
Comments

Join the conversation!

Just In

RE: Opera browser dinged by code execution flaw
efsane Updated - 8th Apr 2011
Great! !! thanks for sharing this information to us!
sesli sohbet sesli chat
0 Votes
+ -
Just think.
Erroneous 28th Oct 2009
MS is being forces to promote these things in Europe.
0 Votes
+ -
Just think.
AzuMao 28th Oct 2009
For every single flaw in one of "these things",
there are over a dozen in IE.
0 Votes
+ -
Opera is great.
CounterEthicsCommissioner-23034636492738337469105860790963 28th Oct 2009
Ultimately customizable, fast, and for some reason (have no clue why) all pages are crisper/more clear on Opera than on other browsers. Maybe a font issue - no clue tho.
0 Votes
+ -
So what about 8 users worldwide at risk?
Johnny Vegas 28th Oct 2009
As was pointed out recently by someone else in another opera thread, no matter how good/fast/secure opera gets, as long as theyre run by a bunch of whining pussies no one wants to use it...
0 Votes
+ -
I make 9
People 28th Oct 2009
.
0 Votes
+ -
I'm #10
[deXter] 30th Oct 2009
0 Votes
+ -
I love Opera...
silversidhe 28th Oct 2009
I have noticed some clunkiness with it lately. I tried to install a different java and I think I screwed it up.
0 Votes
+ -
Is this note worth reading?
hectormacias 28th Oct 2009
Do you post something like this everytime a browser is dinged by code execution flaws, because it happens all the time, and Opera is where it happens the least.
0 Votes
+ -
no
ljenux-23043766007667558234416105604265 29th Oct 2009
for 10 000 security flaws in IE, it's not news.

i guess firefox and opera are so superiror that any flaw is news.

that tells you enough
0 Votes
+ -
Not the only browser
pizzaman7 30th Oct 2009
For the MS haters, IE is not the only browser that needs security updates or has security flaws. They all do.
0 Votes
+ -
Never Ending Browser Vulnerabilities
eiverson@... 30th Oct 2009
All browsers by their nature have and will continue to have numerous security holes, from a recent blog post:

http://www.blueridgenetworks.com/securitynowblog/web-browser-plug-ins-activex-npapi-vulnerabilities-zero-day-exploit-attacks-indefinitely

"The potential number of yet to be discovered programming mistakes that can be exploited by attackers is at least one or two orders of magnitude greater than previously thought. There?s no end in sight to the relentless onslaught of critical vulnerabilities and security patches for web browser users. Worse yet, the vast majority of computers are ill-prepared for the malware attacks that exploit them.

The potential vulnerabilities reside not just in the individual web browsers, their plug-ins, and their supporting library software components but also in the interoperability or communications amongst them. Security penetration/stress testing and cyber crime exploits have historically focused on the individual components."
0 Votes
+ -
Ahhh! Stop the world...
Agnostic_OS 31st Oct 2009
Opera has another vulnerability!
0 Votes
+ -
RE: Opera browser dinged by code execution flaw
efsane Updated - 8th Apr 2011
Great! !! thanks for sharing this information to us!
sesli sohbet sesli chat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix