OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[SA29029] Opera Multiple Vulnerabilities

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Wed Feb 20 2008 - 18:27:05 CST


----------------------------------------------------------------------

A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI
has been released. The new version includes many new and advanced
features, which makes it even easier to stay patched.

Download and test it today:
https://psi.secunia.com/

Read more about this new version:
https://psi.secunia.com/?page=changelog

----------------------------------------------------------------------

TITLE:
Opera Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA29029

VERIFY ADVISORY:
http://secunia.com/advisories/29029/

CRITICAL:
Moderately critical

IMPACT:
Security Bypass, Cross Site Scripting, Exposure of sensitive
information

WHERE:
From remote

SOFTWARE:
Opera 5.x
http://secunia.com/product/82/
Opera 6.x
http://secunia.com/product/81/
Opera 7.x
http://secunia.com/product/761/
Opera 8.x
http://secunia.com/product/4932/
Opera 9.x
http://secunia.com/product/10615/

DESCRIPTION:
Some vulnerabilities have been reported in Opera, which can be
exploited by malicious people to conduct cross-site scripting
attacks, disclose sensitive information, or to bypass certain
security restrictions.

1) A security issue is caused due to a design error when handling
input to file form fields, which can potentially be exploited to
trick a user into uploading arbitrary files.

This is related to #3 in:
SA28758

2) An error within the handling of custom comments in image
properties can be exploited to execute arbitrary script code in the
wrong security context when comments of a malicious image are
displayed.

3) An error in the handling of attribute values when importing XML
into a document can be exploited to bypass filters and conduct
cross-site scripting attacks if these values are used as document
content.

The vulnerabilities are reported in versions prior to 9.26.

SOLUTION:
Update to version 9.26.
http://www.opera.com/download/

PROVIDED AND/OR DISCOVERED BY:
The vendor credits:
1) Mozilla
2) Max Leonov
3) Arnaud

ORIGINAL ADVISORY:
Opera:
http://www.opera.com/support/search/view/877/
http://www.opera.com/support/search/view/879/
http://www.opera.com/support/search/view/880/

OTHER REFERENCES:
SA28758:
http://secunia.com/advisories/28758/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------