Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability
BID:11441
Info
Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability
| Bugtraq ID: | 11441 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1615 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery is credited to Michal Zalewski. |
| Vulnerable: |
Opera Software Opera Web Browser 7.54 Opera Software Opera Web Browser 7.53 Opera Software Opera Web Browser 7.52 Opera Software Opera Web Browser 7.51 Opera Software Opera Web Browser 7.50 Opera Software Opera Web Browser 7.23 Opera Software Opera Web Browser 7.22 Opera Software Opera Web Browser 7.21 Opera Software Opera Web Browser 7.20 Beta 1 build 2981 Opera Software Opera Web Browser 7.20 Opera Software Opera Web Browser 7.11 j Opera Software Opera Web Browser 7.11 b Opera Software Opera Web Browser 7.11 Opera Software Opera Web Browser 7.10 Opera Software Opera Web Browser 7.0 win32 Beta 2 Opera Software Opera Web Browser 7.0 win32 Beta 1 Opera Software Opera Web Browser 7.0 win32 Opera Software Opera Web Browser 7.0 3win32 Opera Software Opera Web Browser 7.0 2win32 Opera Software Opera Web Browser 7.0 1win32 Opera Software Opera Web Browser 6.10 linux Opera Software Opera Web Browser 6.0.5 win32 Opera Software Opera Web Browser 6.0.4 win32 Opera Software Opera Web Browser 6.0.3 win32 Opera Software Opera Web Browser 6.0.3 linux Opera Software Opera Web Browser 6.0.2 win32 Opera Software Opera Web Browser 6.0.2 linux Opera Software Opera Web Browser 6.0.1 win32 Opera Software Opera Web Browser 6.0.1 linux Opera Software Opera Web Browser 6.0.1 Opera Software Opera Web Browser 6.0 win32 Opera Software Opera Web Browser 6.0 6 Opera Software Opera Web Browser 6.0 .6win32 Opera Software Opera Web Browser 6.0 |
| Not Vulnerable: | |
Discussion
Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability
A memory corruption vulnerability exists in Opera. This issue may be triggered if an excessive COL SPAN is specified in the TBODY tag. The issue could result in a minor denial of service condition.
A memory corruption vulnerability exists in Opera. This issue may be triggered if an excessive COL SPAN is specified in the TBODY tag. The issue could result in a minor denial of service condition.
Exploit / POC
Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability
This issue was discovered with the mangleme Web fuzzer:
http://lcamtuf.coredump.cx/soft/mangleme.tgz
The following proof-of-concept is also available:
http://lcamtuf.coredump.cx/mangleme/gallery/opera_die1.html
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
This issue was discovered with the mangleme Web fuzzer:
http://lcamtuf.coredump.cx/soft/mangleme.tgz
The following proof-of-concept is also available:
http://lcamtuf.coredump.cx/mangleme/gallery/opera_die1.html
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability
Solution:
This issue will be reportedly addressed in Opera 7.60.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue will be reportedly addressed in Opera 7.60.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability
References:
References: