Opera Web Browser 'Content-Length' Header Integer Overflow Vulnerability
BID:38519
Info
Opera Web Browser 'Content-Length' Header Integer Overflow Vulnerability
| Bugtraq ID: | 38519 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1349 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Marcin Ressel. Additional details provided by Secunia. |
| Vulnerable: |
Opera Software Opera Web Browser 10.50 Opera Software Opera Web Browser 10.10 Opera Software Opera Web Browser 10.1 Opera Software Opera Web Browser 10.01 Opera Software Opera Web Browser 10 |
| Not Vulnerable: |
Opera Software Opera Web Browser 10.51 |
Discussion
Opera Web Browser 'Content-Length' Header Integer Overflow Vulnerability
Opera Web Browser is prone to a remote integer-overflow vulnerability.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
Update (March 5, 2010): This issue was originally documented as a buffer-overflow vulnerability; however, Opera reports that this issue cannot be exploited to execute arbitrary code.
Update (March 9, 2010): Opera reports that arbitrary code execution may be possible.
Opera Web Browser for Windows versions 10.10 and 10.50 are vulnerable; other versions may also be affected.
Opera Web Browser is prone to a remote integer-overflow vulnerability.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
Update (March 5, 2010): This issue was originally documented as a buffer-overflow vulnerability; however, Opera reports that this issue cannot be exploited to execute arbitrary code.
Update (March 9, 2010): Opera reports that arbitrary code execution may be possible.
Opera Web Browser for Windows versions 10.10 and 10.50 are vulnerable; other versions may also be affected.
Exploit / POC
Opera Web Browser 'Content-Length' Header Integer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to visit a malicious website with the affected browser.
The following proof of concept is available:
To exploit this issue, an attacker must entice an unsuspecting user to visit a malicious website with the affected browser.
The following proof of concept is available:
Solution / Fix
Opera Web Browser 'Content-Length' Header Integer Overflow Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Opera Software Opera Web Browser 10.1
Opera Software Opera Web Browser 10.50
Opera Software Opera Web Browser 10
Opera Software Opera Web Browser 10.01
Opera Software Opera Web Browser 10.10
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Opera Software Opera Web Browser 10.1
-
Opera Software Opera 10.51
http://www.opera.com/browser/download/
Opera Software Opera Web Browser 10.50
-
Opera Software Opera 10.51
http://www.opera.com/browser/download/
Opera Software Opera Web Browser 10
-
Opera Software Opera 10.51
http://www.opera.com/browser/download/
Opera Software Opera Web Browser 10.01
-
Opera Software Opera 10.51
http://www.opera.com/browser/download/
Opera Software Opera Web Browser 10.10
-
Opera Software Opera 10.51
http://www.opera.com/browser/download/
References
Opera Web Browser 'Content-Length' Header Integer Overflow Vulnerability
References:
References:
- Opera 10.51 for Windows changelog (Opera Software)
- Opera Homepage (Opera Software)
- The malformed Content-Length header Security Issue (Yngve Nysæter Pettersen)
- Advisory: HTTP Content-Length header can be used to execute arbitrary code (Opera Software)