Results 1 to 9 of 9
  1. #1
    Experienced User
    Overall activity: 19.0%

    Join Date
    Jun 2008
    Location
    Sri Lanka
    Posts
    1,909
    Liked
    1 times
    Points
    15,911

    Opera Zero Day Remote Code Execution Vulnerability



    Opera 9.61 security update was released last week and fixed a vulnerability in the browser's History Search feature which allowed for remote attackers to read the browser history of the users visiting a maliciously crafted web page. Even though Opera rated this vulnerability as “Extremely Severe”, it seems that they did not properly analyze the flawed resource, as security researchers have just announced a remote code execution vulnerability originating in the same code.

    The new vulnerability was discovered when security researchers Roberto Suggi Liverani, Stefano Di Paola, and Aviv Raff took a closer look at the patched XSS history search vulnerability. Roberto Suggi Liverani, IT Security Consultant at Security Assessment, is also the researcher credited with discovering and reporting the original History Search flaw to Opera.

    The remote code execution is more dangerous than the previous one as it allows for any potentially malicious code to be executed when a user visits a page set up by the attacker. Aviv Raff created a proof of concept exploit page that executes the calc.exe application on Windows machines when it is visited. Even though this example no longer works in 9.61, Raff claims that he has another PoC that does, but he will only release it after Opera fixes the issue. The researcher pointed out that the Linux and Mac OSX versions of Opera are also affected.

    "They should have looked at the code of this local resource for more vulnerabilities. The fixed one is within the displayed links in the searched history. The unfixed one is within the Previous/Next links of the history search page itself," commented Aviv Raff for The Register.

    Opera has been notified about the new flaw and is currently working on a fix which will be included in the 9.62 update. According to Thomas Ford, spokesman for Opera Software, there is no exact release date for Opera 9.62, but he estimates that it will come very soon.

    The Register reports that Mr. Ford also commented on the latest security issues discovered. "We always appreciate people digging and looking for security vulnerabilities in our products. We want them to be as robust as they can be," he stated.

  2. #2
    Experienced User
    Overall activity: 0%

    Join Date
    Sep 2007
    Location
    Newcastle, United Kingdom
    Posts
    2,627
    Liked
    0 times
    Points
    26,726
    Opera... holy !"£$$ thats my browser

  3. #3
    Experienced User
    Overall activity: 19.0%

    Join Date
    Jun 2008
    Location
    Sri Lanka
    Posts
    1,909
    Liked
    1 times
    Points
    15,911
    dont worry the issue has been fixed. no wonder opera relesed updates rapidly

  4. #4
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Location
    India
    Posts
    2,445
    Liked
    31 times
    Points
    13,499
    Yes, Opera and Mozilla are fast in selivering updates.

  5. #5
    Experienced User
    Overall activity: 19.0%

    Join Date
    Jun 2008
    Location
    Sri Lanka
    Posts
    1,909
    Liked
    1 times
    Points
    15,911
    thats where ie falls back. they currently have a lot of truble with mcafee softwares which both people arnt bothered to fix quikly though they know it.

  6. #6
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Location
    Australia
    Posts
    3,884
    Liked
    0 times
    Points
    20,463
    I still can't believe Mozilla already has released a beta for Firefox 3.1

  7. #7
    Experienced User
    Overall activity: 19.0%

    Join Date
    Jun 2008
    Location
    Sri Lanka
    Posts
    1,909
    Liked
    1 times
    Points
    15,911
    the privet browsing thing is still to come. hope its on beta2. i heard it was under heavy tesing 6 months ago

  8. #8
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Location
    Australia
    Posts
    3,884
    Liked
    0 times
    Points
    20,463
    Yer my brother will love p0rn mode and sometimes I don't want people looking at my sites.

  9. #9
    Experienced User
    Overall activity: 0%

    Join Date
    Jun 2008
    Location
    India
    Posts
    2,445
    Liked
    31 times
    Points
    13,499
    I am too waiting for Firefox 3.1 B2. I think Firefox 3.1 Final will be released near IE 8 Final release date

 

 

Similar Threads

  1. Replies: 0
    Last Post: 06-23-2011, 12:46 AM
  2. Replies: 2
    Last Post: 09-11-2010, 04:09 AM
  3. Replies: 10
    Last Post: 07-22-2010, 01:57 AM
  4. Replies: 2
    Last Post: 05-20-2010, 01:30 AM
  5. Replies: 0
    Last Post: 04-29-2010, 07:46 AM
All times are GMT +8. The time now is 10:09 AM.