CERT-In Advisory
CIAD-2009-0051
Multiple Vulnerabilities in Opera
Original Issue Date: November 10, 2009
Severity Rating: High
Systems Affected
- Opera versions prior to 10.01
Overview
Multiple vulnerabilities have been reported in Opera, which could be exploited by remote attacker to bypass certain security restrictions, disclose sensitive information, execute an arbitrary code and conduct spoofing attacks or compromise a user's system.
Description
1. Domain names arbitrary code execution Vulnerability
(
CVE-2009-3831
)
This vulnerability is caused due to improper handling of domain names in Opera. A remote attacker could exploit this vulnerability by tricking a user to visit a specially crafted Web page to trigger memory corruption error. Successful exploitation of this vulnerability could allow a remote attacker to execute an arbitrary code.
2. Web fonts Spoofing Vulnerability
(
CVE-2009-3832
)
This vulnerability is caused due to improper handling of Web fonts intended for use as page content in Opera. A remote attacker could exploit this vulnerability by tricking a user to visit a specially crafted Web page to spoof the domain name. Successful exploitation of this vulnerability could allow a remote attacker to spoof the address field.
Solution
Upgrade to Opera 10.01 or later
http://www.opera.com/download/
Vendor Information
Opera
http://www.opera.com/download/
References
Opera
http://www.opera.com/support/kb/view/940/
http://www.opera.com/support/kb/view/938/
ISS XFORCE
http://xforce.iss.net/xforce/xfdb/54020
http://xforce.iss.net/xforce/xfdb/54022
VUPEN Security
http://www.vupen.com/english/advisories/2009/3073
SecurityFocus
http://www.securityfocus.com/bid/36850
Secunia
http://secunia.com/advisories/37182/1/
CVE Name
CVE-2009-3832
CVE-2009-3831
CWE Name
CWE-94
CWE-20
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|