CyberInsecure.com

Daily cyber threats and internet security news: network security, online safety and latest security alerts
December 16th, 2008

Extremely Severe Vulnerabilities Patched In Opera Browser

Opera released an update to its popular web browser on Tuesday that fixes vulnerabilities it described as “extremely severe”. The update fixes seven security bugs, some of which were previously known.

Version 9.63 of the browser addresses separate code injection risks stemming from flaws in HTML parsing and text input. A critical bug with similar arbitrary code injection risks involving the handling of long host names in files has also been patched. The latest version of the software also lances a cross-site scripting flaw, involving XSLT templates, as well as bugs in feed preview.

Fixed vulnerabilities in Opera 9.63 include:

Manipulating text input contents can allow execution of arbitrary code.

HTML parsing flaw can cause Opera to execute arbitrary code.

Long hostnames in file: URLs can cause execution of arbitrary code.

Script injection in feed preview can reveal contents of unrelated news feeds.

Built-in XSLT templates can allow cross-site scripting.

Fixed an issue that could reveal random data, as reported by Matthew of Hispasec Sistemas.

SVG images embedded using <img> tags can no longer execute Java or plugin content.

More details of these various fixes can be found on Opera Software’s website. The advisory covers Windows but other versions of the browser running on Mac and Linux also need updating against the similar cross-platform risks.

Share this item with others:

More on CyberInsecure:
  • Critical Flaws Patched In Opera 9.61, New Zero-day Vulnerability Remains Unpatched
  • Two Severe Flaws In Opera Browser
  • 7 Vulnerabilities, Some Are Extremely Severe, Patched In New Opera 9.52
  • Opera Software Fixes Two Security Vulnerabilities In Opera 9.60
  • Opera Software Patches Vulnerabilities In Opera 9.64 And Adds Anti-exploitation Mechanisms

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: Extremely Severe Vulnerabilities Patched In Opera Browser

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.

    *
    To prove you’re a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.