Opera discloses two fresh flaws

By

Opera Software released two security advisories for Opera vulnerabilities that could allow attackers to remotely execute code on affected systems.

Opera discloses two fresh flaws
The flaws were found by VeriSign's iDefense Labs to affect Opera 9.02 and believed to affect earlier versions. It affects the browser on both Windows and Linux platforms.

The first vulnerability is a defect in Opera's Javascript SVG implementation - the browser allows improper objects to be passed on to a certain function, allowing execution of arbitrary code on a host system.

The second is a flaw in the way the system handles JPEGs, making it open to a heap-based buffer overflow from a malicious file.

Opera ranks these problems as "moderate," but experts at Secunia categorised them as "highly critical." Users are encouraged to upgrade to Opera 9.1, for which Opera Software corrected the problem.

Click here to email West Coast Bureau Chief Ericka Chickowski.
Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

First npm worm "Shai-Hulud" released in supply chain attack

First npm worm "Shai-Hulud" released in supply chain attack

"VoidProxy" PhishKit targets Google and Microsoft users

"VoidProxy" PhishKit targets Google and Microsoft users

Actor auth tokens gave Global Admin access across Azure Entra ID tenants

Actor auth tokens gave Global Admin access across Azure Entra ID tenants

NSW gov third party-linked cyber incidents quadruple in two years

NSW gov third party-linked cyber incidents quadruple in two years

Log In

  |  Forgot your password?