Opera HREF Malformed Server Name Heap Corruption Vulnerability
BID:8853
Info
Opera HREF Malformed Server Name Heap Corruption Vulnerability
| Bugtraq ID: | 8853 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0870 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2003 12:00AM |
| Updated: | Jul 11 2009 11:56PM |
| Credit: | The discovery of this issue has been credited to @stake. |
| Vulnerable: |
Opera Software Opera Web Browser 7.20 Opera Software Opera Web Browser 7.11 |
| Not Vulnerable: |
Opera Software Opera Web Browser 7.21 |
Discussion
Opera HREF Malformed Server Name Heap Corruption Vulnerability
A vulnerability has been discovered in the Opera web browser that could lead to remote code execution. The problem is said to trigger when handling malformed HTML HREF values and may result in a buffer overrun occuring within heap memory. As a result of this issue, an attacker may be capable of executing arbitrary code on a victim user by coaxing them to a malicious web site, or possibly by transmitting a malicious HTML e-mail message to an Opera mail client.
A vulnerability has been discovered in the Opera web browser that could lead to remote code execution. The problem is said to trigger when handling malformed HTML HREF values and may result in a buffer overrun occuring within heap memory. As a result of this issue, an attacker may be capable of executing arbitrary code on a victim user by coaxing them to a malicious web site, or possibly by transmitting a malicious HTML e-mail message to an Opera mail client.
Exploit / POC
Opera HREF Malformed Server Name Heap Corruption Vulnerability
The following proof-of-concept HTML example has been supplied to demonstrate this issue:
<a href="file://server%%[many % characters]%%text" ></a>
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof-of-concept HTML example has been supplied to demonstrate this issue:
<a href="file://server%%[many % characters]%%text" ></a>
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Opera HREF Malformed Server Name Heap Corruption Vulnerability
Solution:
Gentoo has released an advisory that includes updates to address this issue. The following commands may be used to apply these updates:
emerge --sync
emerge '>=net-www/opera-7.22'
emerge clean
The vendor has released Opera 7.21 to address this issue. Users are urged to upgrade as soon as possible.
Opera Software Opera Web Browser 7.11
Opera Software Opera Web Browser 7.20
Solution:
Gentoo has released an advisory that includes updates to address this issue. The following commands may be used to apply these updates:
emerge --sync
emerge '>=net-www/opera-7.22'
emerge clean
The vendor has released Opera 7.21 to address this issue. Users are urged to upgrade as soon as possible.
Opera Software Opera Web Browser 7.11
-
Opera Software Opera 7.21
http://www.opera.com/download/
Opera Software Opera Web Browser 7.20
-
Opera Software Opera 7.21
http://www.opera.com/download/
References
Opera HREF Malformed Server Name Heap Corruption Vulnerability
References:
References: