Opera Web Browser Remote Code Execution and Information Disclosure Vulnerabilities
BID:30068
Info
Opera Web Browser Remote Code Execution and Information Disclosure Vulnerabilities
| Bugtraq ID: | 30068 |
| Class: | Unknown |
| CVE: |
CVE-2008-3078 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2008 12:00AM |
| Updated: | Aug 08 2008 05:46PM |
| Credit: | Billy Rios and Philip Taylor |
| Vulnerable: |
S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 Opera Software Opera Web Browser 9.50 beta Opera Software Opera Web Browser 9.5 Opera Software Opera Web Browser 9.27 Opera Software Opera Web Browser 9.26 Opera Software Opera Web Browser 9.25 Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 beta 1 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 |
| Not Vulnerable: |
Opera Software Opera Web Browser 9.51 |
Discussion
Opera Web Browser Remote Code Execution and Information Disclosure Vulnerabilities
Opera Web Browser is prone to multiple security vulnerabilities, including a remote code-execution issue and an information-disclosure issue.
Successful exploits of these issues may allow remote attackers to execute arbitrary code in the context of the application or obtain potentially sensitive information.
Versions prior to Opera 9.51 are vulnerable.
Opera Web Browser is prone to multiple security vulnerabilities, including a remote code-execution issue and an information-disclosure issue.
Successful exploits of these issues may allow remote attackers to execute arbitrary code in the context of the application or obtain potentially sensitive information.
Versions prior to Opera 9.51 are vulnerable.
Exploit / POC
Opera Web Browser Remote Code Execution and Information Disclosure Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Opera Web Browser Remote Code Execution and Information Disclosure Vulnerabilities
Solution:
The vendor released Opera 9.51 to address these issues. Please see the references for more information.
Opera Software Opera Web Browser 9.50 beta
Opera Software Opera Web Browser 9.20 beta 1
Opera Software Opera Web Browser 9.25
Opera Software Opera Web Browser 9.27
Opera Software Opera Web Browser 9.23
Opera Software Opera Web Browser 9
Opera Software Opera Web Browser 9.26
Opera Software Opera Web Browser 9.20
Opera Software Opera Web Browser 9.22
Opera Software Opera Web Browser 9.24
Opera Software Opera Web Browser 9.02
Opera Software Opera Web Browser 9.01
Opera Software Opera Web Browser 9.5
Opera Software Opera Web Browser 9.10
Opera Software Opera Web Browser 9.21
Solution:
The vendor released Opera 9.51 to address these issues. Please see the references for more information.
Opera Software Opera Web Browser 9.50 beta
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.20 beta 1
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.25
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.27
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.23
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.26
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.20
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.22
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.24
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.02
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.01
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.5
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.10
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
Opera Software Opera Web Browser 9.21
-
Opera Software Opera Download
http://www.opera.com/download/index.dml?custom=yes
References
Opera Web Browser Remote Code Execution and Information Disclosure Vulnerabilities
References:
References:
- Opera Homepage (Opera Software)
- Advisory: canvas functions can reveal data from random places in memory (Opera Software)
- Opera 9.51 Changelog (Opera Software)