Category Archives: advisory

Sites using revoked intermediate certificates might be shown as secure – Opera Security Advisories

Summary Opera does not check the revocation status for intermediate certificates not served by the server. If the intermediate is revoked, this might not impact the security rating in Opera, and the site might be shown as secure. Severity Moderately severe Opera’s Response Opera Software has released Opera 10.00, where this issue has been fixed.

Random number generator and input name linebreaks can be used to send custom data to other sites – Opera Security Advisories

Severity Moderately severe Problem description Input names can contain line breaks when data is sent using POST. Suitable use of the random number generator can reveal predictable boundaries that will be used when sending the POST data. These can be combined to add extra boundaries into the data, containing payloads that may confuse the receiving…

Specially crafted JPEG images can be used to execute arbitrary code – Opera Security Advisories

Severity Extremely Severe Problem Description Specially crafted JPEG images can cause Opera to corrupt memory and crash. Successful exploitation can lead to execution of arbitrary code. Opera’s Response Opera Software has released Opera 9.64, where this issue has been fixed. Credits Thanks to Tavis Ormandy of the Google Security Team for reporting this issue to…

TLS certificates can be used to execute arbitrary code – Opera Security Advisories

Severity Highly Severe Problem Description When connecting to a TLS-protected website, Opera parses the X.509 certificate. If a site uses a specially crafted Subject Alternative Name in the certificate, it can cause Opera to crash. To inject code, additional means will have to be employed. Opera’s Response Opera Software has released Opera 9.25, where this…

Certain characters can be used to allow cross-site scripting – Opera Security Advisories

Severity Highly Severe Problem Description When accepting HTML content from untrusted users, Web sites sometimes employ some kind of filtering to ensure that the content cannot contain scripts. If the content is to be used inside an HTML attribute, characters that separate attributes need to be filtered out to prevent scripted attributes from being created. Due…

Vulnerability in createSVGTransformFromMatrix (JavaScript, SVG) – Opera Security Advisories

Summary A vulnerability in createSVGTransformFromMatrix ObjectTypecasting can crash Opera. Severity Moderate Problem description Passing an incorrect object to createSVGTransformFromMatrixcan crash Opera and enable arbitrary code execution. Users who have disabled JavaScript are not affected. Opera’s response Opera has released version 9.10, where this flaw has beencorrected. Credits Thanks to iDefense Labs for notifying Opera Softwareabout this…