Opera Web Browser Bitmap File RLE Remote Denial Of Service Vulnerability
BID:26721
Info
Opera Web Browser Bitmap File RLE Remote Denial Of Service Vulnerability
| Bugtraq ID: | 26721 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-6523 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2007 12:00AM |
| Updated: | Jan 08 2008 04:19PM |
| Credit: | Gynvael Coldwind of Vexillium and Simey is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 Opera Software Opera Web Browser 9.50 beta Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 beta 1 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 |
| Not Vulnerable: |
Opera Software Opera Web Browser 9.25 |
Discussion
Opera Web Browser Bitmap File RLE Remote Denial Of Service Vulnerability
Opera Web Browser is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue will allow an attacker to cause the application to stop responding, denying further service to legitimate users.
This issue affects Opera 9.50 beta and 9.24; other versions may also be affected.
Opera Web Browser is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue will allow an attacker to cause the application to stop responding, denying further service to legitimate users.
This issue affects Opera 9.50 beta and 9.24; other versions may also be affected.
Exploit / POC
Opera Web Browser Bitmap File RLE Remote Denial Of Service Vulnerability
A proof of concept is available at the following URI. Symantec has not verified the integrity of this example. Use caution when handling such examples.
http://gynvael.vexillium.org/opera_dos/
A proof of concept is available at the following URI. Symantec has not verified the integrity of this example. Use caution when handling such examples.
http://gynvael.vexillium.org/opera_dos/
Solution / Fix
Opera Web Browser Bitmap File RLE Remote Denial Of Service Vulnerability
Solution:
The vendor has released Opera 9.25 to address this issue. Please see the referenced advisories for further information.
Solution:
The vendor has released Opera 9.25 to address this issue. Please see the referenced advisories for further information.
References
Opera Web Browser Bitmap File RLE Remote Denial Of Service Vulnerability
References:
References:
- Changelog for Opera 9.25 for Windows (Opera Software)
- Opera Homepage (Opera Software)
- Opera 9.50 beta and prior remote DoS (freeze) ([email protected])