Opera Username URI Warning Dialog Buffer Overflow Vulnerability
BID:6811
Info
Opera Username URI Warning Dialog Buffer Overflow Vulnerability
| Bugtraq ID: | 6811 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2003 12:00AM |
| Updated: | Feb 10 2003 12:00AM |
| Credit: | Discovery of this issue is credited to nesumin <[email protected]>. |
| Vulnerable: |
Opera Software Opera Web Browser 7.0 win32 Beta 2 Opera Software Opera Web Browser 7.0 win32 Beta 1 Opera Software Opera Web Browser 6.0.5 win32 Opera Software Opera Web Browser 6.0 .6win32 |
| Not Vulnerable: |
Opera Software Opera Web Browser 7.0 win32 Opera Software Opera Web Browser 7.0 1win32 |
Discussion
Opera Username URI Warning Dialog Buffer Overflow Vulnerability
The Opera browser for Win32 (and possibly other) systems is prone to a remotely exploitable buffer overflow condition. For security purposes, Opera will display a warning any time a user of the client visits a link containing a username as part of the URI. An excessively long username will trigger a buffer overflow condition related to this security feature that may overwrite the stack frame of the affected function. Attackers may exploit this vulnerability to execute instructions on client systems.
The Opera browser for Win32 (and possibly other) systems is prone to a remotely exploitable buffer overflow condition. For security purposes, Opera will display a warning any time a user of the client visits a link containing a username as part of the URI. An excessively long username will trigger a buffer overflow condition related to this security feature that may overwrite the stack frame of the affected function. Attackers may exploit this vulnerability to execute instructions on client systems.
Exploit / POC
Opera Username URI Warning Dialog Buffer Overflow Vulnerability
A proof-of-concept utility has been released which will generate a HTML file to reproduce the vulnerability.
A proof-of-concept utility has been released which will generate a HTML file to reproduce the vulnerability.
References
Opera Username URI Warning Dialog Buffer Overflow Vulnerability
References:
References:
- Opera Web Browser Home Page (Opera Software)
- Opara 6.06 Released, Security-Hole Left (nesumin
) - Opera Username Buffer Overflow Vulnerability (nesumin
)