Category Archives: advisory

DOM events manipulation might be used to execute arbitrary code – Opera Security Advisories

Severity: High Description: Particular DOM event manipulations can cause Opera to crash. In some cases, this crash might occur in a way that allows execution of arbitrary code. To inject code, additional techniques would have to be employed. Opera’s response: Opera Software has released Opera 12.13, where this issue has been fixed. Credits: Thanks to…

Repeated attempts to access a target site can trigger address field spoofing – Opera Security Advisories

Severity Low Description The browser address field should always show the correct address for the page that is currently being displayed. By making repeated requests to load a target site in rapid succession, an attacking web site can cause Opera to display the target sites address while the attacking page is still being displayed. During…

Private data can be disclosed to other computer users, or be modified by them – Opera Security Advisories

Severity High Description Private data such as cache, password files, and Opera’s configuration files are supposed to be visible only to the user who owns the Opera profile. Opera does not set the profile folder permissions correctly, allowing other computer users to read the sensitive contents of profile files. In some cases, other computer users…

Malformed GIF images could allow execution of arbitrary code – Opera Security Advisories

Severity  Critical  Description  When loading GIF images into memory, Opera should allocate the correct amount of memory to store that image. Specially crafted image files can cause Opera to allocate the wrong amount of memory. Subsequent data may then overwrite unrelated memory with attacker-controlled data. This can lead to a crash, which may also execute…