Category Archives: advisory

Malformed bitmaps can reveal old data from random places in memory – Opera Security Advisories

Severity Moderately Severe Problem Description Specially malformed bitmap images can cause Opera to render the image using a palette made up from uninitialized memory. Using canvas, the pattern can be read and analyzed by JavaScript, so an attacker can get random samples of the user’s memory, which may contain data. Opera’s Response Opera Software has…

Rich editing allows cross domain scripting – Opera Security Advisories

Problem Description Rich editing using designMode allows page contents to be edited. Pages can use this ability to inject scripts into pages from other domains. This allows cross domain scripting. Opera’s Response Opera Software has released Opera 9.25, where this issue has been fixed. Credits Thanks to David Bloom for reporting this issue to Opera…

Character Encoding Inheritance in iframes Can Enable Cross-Site Scripting – Opera Security Advisories

Severity Moderate  Problem description Pages displayed inside an iframe will inherit the character encodingof the parent page, unless they specify their own character encoding.A malicious page that uses the UTF-7 character encoding can includeother sites, for example inside iframes. This can be exploited toperform cross-site scripting on certain sites, allowing the attackerto get access to…

Long hostnames in file: URLs can cause execution of arbitrary code – Opera Security Advisories

Severity Highly Severe Problem Description Exceptionally long host names in file: URLs can cause a buffer overflow, which may be exploited to execute arbitrary code. Remote Web pages cannot refer to file: URLs, so successful exploitation involves tricking users into manually opening the exploit URL, or a local file that refers to it. Opera’s Response…

HTML parsing flaw can cause Opera to execute arbitrary code – Opera Security Advisories

Severity Extremely Severe Problem Description Certain HTML constructs can cause the resulting DOM to change unexpectedly, which triggers a crash. To inject code, additional techniques will have to be employed. Opera’s Response Opera Software has released Opera 9.63, where this issue has been fixed. Credits Thanks to Alexios Fakos for reporting this issue to Opera…

Pages held in frames are able to change the location of pages in unrelated frames on the parent page – Opera Security Advisories

Severity: Less Severe Problem Description: Pages from different sources held on the same parent page should not be able to modify the locations of each other. In affected Opera versions, if a page contains frames from both a trusted but not secured, and an untrusted source, the untrusted page is able to replace the contents of a…

Certain characters can obscure the page address – Opera Security Advisories

Severity: Less SevereProblem DescriptionWhen a page address contains certain characters, they can cause the page address text to be misplaced. In some cases, this could make characters be indistinguishable from each other, allowing some site addresses to look like other site addresses.Opera’s ResponseOpera Software has released Opera 9.26, where this issue has been fixed.CreditsThanks to…