Opera Web Browser 'file://' Heap Based Buffer Overflow Vulnerability
BID:32323
Info
Opera Web Browser 'file://' Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 32323 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-5178 CVE-2008-5680 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2008 12:00AM |
| Updated: | Mar 17 2009 01:16PM |
| Credit: | send9 |
| Vulnerable: |
Opera Software Opera Web Browser 9.62 Opera Software Opera Web Browser 9.61 Opera Software Opera Web Browser 9.60 beta 1 Opera Software Opera Web Browser 9.60 Opera Software Opera Web Browser 9.52 Opera Software Opera Web Browser 9.51 Opera Software Opera Web Browser 9.50 beta Opera Software Opera Web Browser 9.5 Opera Software Opera Web Browser 9.27 Opera Software Opera Web Browser 9.26 Opera Software Opera Web Browser 9.25 Opera Software Opera Web Browser 9.24 Opera Software Opera Web Browser 9.23 Opera Software Opera Web Browser 9.22 Opera Software Opera Web Browser 9.21 Opera Software Opera Web Browser 9.20 beta 1 Opera Software Opera Web Browser 9.20 Opera Software Opera Web Browser 9.10 Opera Software Opera Web Browser 9.02 Opera Software Opera Web Browser 9.01 Opera Software Opera Web Browser 9 Gentoo Linux |
| Not Vulnerable: |
Opera Software Opera Web Browser 9.63 |
Discussion
Opera Web Browser 'file://' Heap Based Buffer Overflow Vulnerability
Opera Web Browser is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it to an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Opera Web Browser 9.62 is vulnerable; other versions may also be affected.
Opera Web Browser is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it to an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Opera Web Browser 9.62 is vulnerable; other versions may also be affected.
Exploit / POC
Opera Web Browser 'file://' Heap Based Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Opera Web Browser 'file://' Heap Based Buffer Overflow Vulnerability
Solution:
The vendor released an advisory to address this issue. Please see the references for more information.
Solution:
The vendor released an advisory to address this issue. Please see the references for more information.
References
Opera Web Browser 'file://' Heap Based Buffer Overflow Vulnerability
References:
References:
- Opera Homepage (Opera Software)
- Security changes since Opera 9.62 (Opera Software)
- Opera 9.6x file:// overflow ([email protected])
- Re: Opera 9.6x file:// overflow ([email protected])
- Re: Re: Re: Opera 9.6x file:// overflow ([email protected])
- Re: Re: Re: Re: Opera 9.6x file:// overflow ("[email protected]"
) - Advisory: Long hostnames in file: URLs can cause execution of arbitrary code (Opera Software)