Opera Web Browser Java Implementation Multiple Remote Vulnerabilities
BID:11712
Info
Opera Web Browser Java Implementation Multiple Remote Vulnerabilities
| Bugtraq ID: | 11712 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2004 12:00AM |
| Updated: | Nov 19 2004 12:00AM |
| Credit: | Disclosure of these issues is credited to Marc Schoenefeld <[email protected]>. |
| Vulnerable: |
Opera Software Opera Web Browser 7.54 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Opera Web Browser Java Implementation Multiple Remote Vulnerabilities
Multiple remote vulnerabilities reportedly affect the Opera Web Browser Java implementation. These issues are due to the insecure proprietary design of the Web browser's Java implementation.
These issues may allow an attacker to craft a Java applet that violate Sun's Java secure programming guidelines.
These issues may be leveraged to carry out a variety of unspecified attacks including sensitive information disclosure and denial of service attacks. Any successful exploitation would take place with the privileges of the user running the affected browser application.
Although only version 7.54 is reportedly vulnerable, it is likely that earlier versions are vulnerable to these issues as well.
Multiple remote vulnerabilities reportedly affect the Opera Web Browser Java implementation. These issues are due to the insecure proprietary design of the Web browser's Java implementation.
These issues may allow an attacker to craft a Java applet that violate Sun's Java secure programming guidelines.
These issues may be leveraged to carry out a variety of unspecified attacks including sensitive information disclosure and denial of service attacks. Any successful exploitation would take place with the privileges of the user running the affected browser application.
Although only version 7.54 is reportedly vulnerable, it is likely that earlier versions are vulnerable to these issues as well.
Exploit / POC
Opera Web Browser Java Implementation Multiple Remote Vulnerabilities
The following exploits have been made available. The first exploit will crash the affected browser by generating an assertion error through attempted access to fonts, the second exploit will trigger a denial of service condition by manipulating process memory, the third exploit will reveal the installation path of the Java SDK, and finally the last exploit will reveal the currently authenticated user, the user's directory contents and the host operating system.
The following exploits have been made available. The first exploit will crash the affected browser by generating an assertion error through attempted access to fonts, the second exploit will trigger a denial of service condition by manipulating process memory, the third exploit will reveal the installation path of the Java SDK, and finally the last exploit will reveal the currently authenticated user, the user's directory contents and the host operating system.
Solution / Fix
Opera Web Browser Java Implementation Multiple Remote Vulnerabilities
Solution:
The vendor has released fixes to address this and other issues.
Gentoo has released an advisory (GLSA 200502-17) and an updated eBuild to address this and other issues in the Opera Web Browser. This update can be installed by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/opera-7.54-r3"
Opera Software Opera Web Browser 7.54
Solution:
The vendor has released fixes to address this and other issues.
Gentoo has released an advisory (GLSA 200502-17) and an updated eBuild to address this and other issues in the Opera Web Browser. This update can be installed by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=net-www/opera-7.54-r3"
Opera Software Opera Web Browser 7.54
-
Opera Software Opera 7.54u2
http://www.opera.com/download/
References
Opera Web Browser Java Implementation Multiple Remote Vulnerabilities
References:
References:
- Changelog for Opera 7.54u1 for Linux (Opera Software)
- Changelog for Opera 7.54u2 for Linux (Opera Software)
- Opera Web Browser Home Page (Opera Software)
- Java Vulnerabilities in Opera 7.54 (Marc Schoenefeld
) - Opera 7.54 vulnerabilities again (still unfixed) (Marc Schoenefeld
)