Severity
Description
When attempting to resolve a URL which cannot be interpreted as a legal URL, Opera will create an error page to display to the user when they load it. If enough invalid URLs can be created, Opera can use up all available disk space with these error pages, causing the browser or operating system to crash. The files will not be removed if this happens, which can cause the system to remain disabled until it is recovered by other means. Exploiting this issue will require the victim to load the attacking page for enough time to generate these files, which may take a very substantial amount of time.
Opera’s response
Opera Software has released Opera 11.50, where this issue has been fixed.
Credits
Thanks to Masahiro Yamada for reporting this issue to Opera Software.
Related external advisories
CVE-2011-1337