CERT-In Advisory
CIAD-2007-0066
Multiple Vulnerabilities in Opera Browser
Original Issue Date: December 28, 2007
Severity Rating: High
Systems Affected
- Opera version 9.24 and prior
Overview
Multiple vulnerabilities have been reported in Opera which could be exploited by remote attacker to cause cross domain scripting, denial of service attack or execute arbitrary code on the affected system.
Description
1. Cross domain scripting vulnerability in Opera
(
CVE-2007-6520
)
A vulnerability has been reported in Opera due to unspecified error related to specific plugins. A remote attacker could exploit the vulnerability by creating specially crafted website and lure user to visit the same to conduct cross-domain scripting attacks. These plugins are used to bypass same origin policy restrictions and gain unauthorized access to other domains.
2. TLS certificate code execution vulnerability in Opera
(
CVE-2007-6521
)
A vulnerability has been reported in Opera due to an unspecified error when handling TLS certificates. This vulnerability could be exploited by remote attackers via specially crafted TLS certificates to execute arbitrary code on the target user's system.
3. Cross domain scripting vulnerability in Opera
(
CVE-2007-6522
)
A vulnerability has been reported in Opera due to an unspecified error within Rich text editing functionality. This vulnerability could be exploited by remote attackers to bypass same origin policy restrictions and gain unauthorized access to other domains by using designMode to modify contents of pages in other domains.
4. Algorithmic complexity vulnerability in opera
(
CVE-2007-6523
)
A vulnerability has been reported in Opera due to algorithmic complexity. This vulnerability could be exploited by remote attackers via a crafted bitmap BMP file that triggers a large number of calculations and checks to cause a denial of service CPU consumption attack.
5. Bitmap information disclosure vulnerability
(
CVE-2007-6524
)
A vulnerability has been reported in Opera due to an unspecified error when processing malformed bitmap images. A remote attacker could exploit this vulnerability to display random memory data and other sensitive information.
Solution
Update to version 9.25.
http://www.opera.com/download/
Vendor Information
Opera
http://www.opera.com/docs/changelogs/linux/925/
http://www.opera.com/docs/changelogs/windows/925/
References
Secunia
http://secunia.com/advisories/28169
FrSirt
http://www.frsirt.com/english/advisories/2007/4261
Securityfocus
http://www.securityfocus.com/archive/1/archive/1/484605/100/200/threaded
Xforce
http://xforce.iss.net/xforce/xfdb/39147
Securitytracker
http://www.securitytracker.com/id?1019131
CVE Name
CVE-2007-6520
CVE-2007-6521
CVE-2007-6522
CVE-2007-6523
CVE-2007-6524
CWE Name
CWE-189
CWE-79
CWE-310
CWE-399
CWE-200
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|