Opera Web Browser Arbitrary Command Execution Vulnerability
BID:15521
Info
Opera Web Browser Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 15521 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2005 12:00AM |
| Updated: | Nov 22 2005 12:00AM |
| Credit: | Discovery is credited to Jakob Balle, Secunia Research. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 Opera Software Opera Web Browser 8.50 Opera Software Opera Web Browser 8.0 2 Opera Software Opera Web Browser 8.0 1 Opera Software Opera Web Browser 8.0 Gentoo Linux |
| Not Vulnerable: |
Opera Software Opera Web Browser 8.51 |
Discussion
Opera Web Browser Arbitrary Command Execution Vulnerability
Opera Web Browser is affected by an arbitrary command execution vulnerability.
User-supplied data passed through a URI is not properly sanitized, allowing an attacker to use a specially crafted URI and enticing a user to follow it to execute arbitrary commands through the shell.
This attack may facilitate unauthorized remote access.
Opera 8.50 and prior versions running on Unix and Linux platforms are vulnerable to this issue. This vulnerability is identical to BID 14888 (Mozilla Browser/Firefox Arbitrary Command Execution Vulnerability).
Opera Web Browser is affected by an arbitrary command execution vulnerability.
User-supplied data passed through a URI is not properly sanitized, allowing an attacker to use a specially crafted URI and enticing a user to follow it to execute arbitrary commands through the shell.
This attack may facilitate unauthorized remote access.
Opera 8.50 and prior versions running on Unix and Linux platforms are vulnerable to this issue. This vulnerability is identical to BID 14888 (Mozilla Browser/Firefox Arbitrary Command Execution Vulnerability).
Exploit / POC
Opera Web Browser Arbitrary Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Opera Web Browser Arbitrary Command Execution Vulnerability
Solution:
Opera 8.51 has been released to address this issue.
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200512-10 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=www-client/opera-8.51"
Opera Software Opera Web Browser 8.0
Opera Software Opera Web Browser 8.0 1
Opera Software Opera Web Browser 8.0 2
Opera Software Opera Web Browser 8.50
Solution:
Opera 8.51 has been released to address this issue.
SUSE advisory SUSE-SR:2005:028 is available to address various issues. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200512-10 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=www-client/opera-8.51"
Opera Software Opera Web Browser 8.0
-
Opera Software Opera Web Browser 8.51
http://www.opera.com/download/
Opera Software Opera Web Browser 8.0 1
-
Opera Software Opera Web Browser 8.51
http://www.opera.com/download/
Opera Software Opera Web Browser 8.0 2
-
Opera Software Opera Web Browser 8.51
http://www.opera.com/download/
Opera Software Opera Web Browser 8.50
-
Opera Software Opera Web Browser 8.51
http://www.opera.com/download/
References
Opera Web Browser Arbitrary Command Execution Vulnerability
References:
References:
- Opera Web Browser Home Page (Opera Software)
- Secunia Research: Opera Command Line URL Shell Command Injection (Secunia Research
)