Opera Web Browser 'SELECT' HTML Tag Remote Memory Corruption Vulnerability
BID:47764
Info
Opera Web Browser 'SELECT' HTML Tag Remote Memory Corruption Vulnerability
| Bugtraq ID: | 47764 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1824 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2011 12:00AM |
| Updated: | May 09 2011 12:00AM |
| Credit: | Jonathan Brossard of Toucan System |
| Vulnerable: |
Opera Software Opera 10.60 |
| Not Vulnerable: |
Opera Software Opera 11.10 Opera Software Opera 10.61 |
Discussion
Opera Web Browser 'SELECT' HTML Tag Remote Memory Corruption Vulnerability
The Opera web browser is prone to a memory-corruption vulnerability.
Remote attackers may exploit this vulnerability to crash the application, causing a denial of service.
Successful exploits may lead to arbitrary code execution; however, this has not been confirmed.
Opera web browser versions 10.60 and prior are vulnerable.
The Opera web browser is prone to a memory-corruption vulnerability.
Remote attackers may exploit this vulnerability to crash the application, causing a denial of service.
Successful exploits may lead to arbitrary code execution; however, this has not been confirmed.
Opera web browser versions 10.60 and prior are vulnerable.
Exploit / POC
Opera Web Browser 'SELECT' HTML Tag Remote Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Opera Web Browser 'SELECT' HTML Tag Remote Memory Corruption Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Opera Web Browser 'SELECT' HTML Tag Remote Memory Corruption Vulnerability
References:
References:
- Product Homepage (Opera)
- TSSA-2011-02 - Opera : SELECT SIZE Arbitrary null write (Toucan System)