This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Opera updates

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Opera v9.22 released

Download:
- http://www.opera.com/download/index.dml?custom=yes

Changelog for Opera 9.22 for Windows
- http://www.opera.com/docs/changelogs/windows/922/#security

> http://www.opera.com/support/search/view/862/

> http://www.opera.com/support/search/view/863/

> http://www.opera.com/support/search/view/864/

————

- http://secunia.com/advisories/26138/
Release Date: 2007-07-19
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: Opera 9.x
…The vulnerability is reported in version 9.21 on Windows. Other versions may also be affected…
Solution: Update to version 9.22.
Original Advisory: Opera:
http://www.opera.com/docs/changelogs/windows/922/ …

.
FYI…

- http://secunia.com/advisories/27277/
Last Update: 2007-10-18
Critical: Highly critical
Impact: Cross Site Scripting, System access
Where: From remote
Solution Status: Vendor Patch
Software: Opera 5.x, Opera 6.x, Opera 7.x, Opera 8.x, Opera 9.x
…The vulnerabilities are reported in all versions of Opera for Desktop prior to version 9.24.
Solution: Update to version 9.24.
http://www.opera.com/download/

Changelog for Opera 9.24
> http://www.opera.com/docs/changelogs/windows/924/

- http://www.opera.com/support/search/view/866/

- http://www.opera.com/support/search/view/867/

.
FYI…

Opera v9.25 released
- http://secunia.com/advisories/28169/
Release Date: 2007-12-19
Critical: Highly critical
Impact: Security Bypass, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch…
Solution: Update to version 9.25.

Opera 9.25
- http://www.opera.com/download/

Changelog
- http://www.opera.com/docs/changelogs/windows/925/

Advisory: Rich editing allows cross domain scripting
- http://www.opera.com/support/search/view/875/
"…Opera Software has released Opera 9.25, where this issue has been fixed…"

:ph34r:
FYI…

Opera v9.26 released
- http://secunia.com/advisories/29029/
Release Date: 2008-02-20
Critical: Moderately critical
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
Software: Opera 5.x, Opera 6.x, Opera 7.x, Opera 8.x, Opera 9.x…
Solution: Update to version 9.26.
> http://www.opera.com/download/

Changelog for Opera 9.26
- http://www.opera.com/docs/changelogs/windows/926/
- Security
> http://www.opera.com/support/search/view/877/
> http://www.opera.com/support/search/view/879/
> http://www.opera.com/support/search/view/880/
- Miscellaneous
* Fixed a stability issue found in Opera 9.0 to 9.25, when Opera connects securely to Windows Server 2008 or other servers supporting the TLS Certificate Status extension.
* Additional stability fixes.
FYI…

Opera v9.27 released
- http://www.opera.com/download/
April 3, 2008

Release Notes
- http://www.opera.com/docs/changelogs/windows/927/#security
"This release is a recommended security and stability upgrade…"

- http://www.securityfocus.com/bid/28585/solution
Updated: Apr 12 2008 - "…The vendor released Opera 9.27 to address these issues…"

- http://www.opera.com/support/search/view/881/
- http://www.opera.com/support/search/view/882/

- http://secunia.com/advisories/29662/
Release Date: 2008-04-03
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status:Vendor Patch
…Successful exploitation of the vulnerabilities may allow execution of arbitrary code. The vulnerabilities are reported in versions prior to 9.27.
Solution: Update to version 9.27.

:ph34r:
FYI…

- http://www.eweek.com/c/a/Security/Opera-Bo…are-Protection/
2008-06-06 - "Opera has beefed up security in its upcoming Web browser as it looks to challenge Firefox and Internet Explorer in the area of Web security. Putting a bulls-eye on Web-based threats, the Opera has formed a partnership with Haute Secure*, a Seattle-based security vendor founded in 2006, to protect users from rogue sites known to distribute malware as well as from links users might click on and download malicious software. The fruits of this union will bear in Opera 9.5… Opera users can choose to send information back to Haute Secure or Opera’s anti-phishing partners, Netcraft, PhishTank. Haute Secure also gets Google's malware data, which is the sole data source for Firefox 3…"
* http://hautesecure.com/index.aspx

(Opera -current- stable release is v9.27)
FYI…

Opera 9.50 released
- http://www.opera.com/download/

- http://www.opera.com/docs/changelogs/windows/950/
"…Opera 9.5 is a recommended security and stability upgrade…"

- http://www.opera.com/docs/changelogs/windows/950/#security
Security:
* Fixed an issue where certain characters could obscure the page address, as reported by Tony Thomas…
* Solved an issue where Images could be read cross-domain with canvas, as reported by Philip Taylor…
* Pages held in frames are no longer able to change the location of pages in unrelated frames on the parent page…
* Improved Fraud Protection now includes advanced malware prevention and upgraded phishing detection technologies…
* Added support for Extended Validation (EV) certificates.
* Added automatic downloading of trusted root certificates when required.
* Disabled SSL v2 and weak ciphers.
* Improvements made to certificate handling, the new certificate repository and the certificates UI.
* Introduced a new security notification scheme in the address field:
o gold lock on green field for secure sites with Extended Validation
o silver lock on yellow field for regular secure sites
o question mark on gray field for HTTPS sites with issues
o no notification for normal sites
o fraud warning on red field for blacklisted sites
* Opera now distinguishes between local servers on localhost, intranet servers, and remote servers on the Internet.
o Local servers can use remote resources, but not vice versa…

- http://secunia.com/advisories/30636/
Release Date: 2008-06-12
Critical: Less critical
Impact: Spoofing, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
…The vulnerabilities are reported in versions prior to 9.5…
Solution: Update to version 9.5…
http://www.opera.com/download/

:ph34r:
FYI…

Opera 9.51 released
- http://www.opera.com/download/
03.07.2008

Release Notes:
- http://www.opera.com/docs/changelogs/windows/951/#security
"Opera 9.51 is a recommended security and stability upgrade…
Miscellaneous
* Corrected a stability issue with Yahoo! Mail.
* TinyMCE 2.1.x editor now works properly.
* Printing of chat items has been improved.
* Reconnection of the IRC client has been adjusted and improved.
* Menus on deviantart.com now work properly.
* Eliminated unwanted line breaks in rich text editors.
Windows-specific changes
* Fixed a resource leak in the transfer window that could cause visual paint problems and other related problems.
* Command line parameters must now be specified before any URLs on the command line…

- http://www.opera.com/support/search/view/887/

- http://secunia.com/advisories/30937/
Release Date: 2008-07-03
Critical: Highly critical…

:ph34r:
FYI…

Opera 9.52 released
- http://www.opera.com/download/

Changelog
- http://www.opera.com/docs/changelogs/windows/952/
Opera 9.52 is a recommended security and stability upgrade…

Security advisories:
- http://www.opera.com/support/search/view/892/
- http://www.opera.com/support/search/view/893/
- http://www.opera.com/support/search/view/894/
- http://www.opera.com/support/search/view/895/
- http://www.opera.com/support/search/view/896/
- http://www.opera.com/support/search/view/897/

- http://secunia.com/advisories/31549/
Release Date: 2008-08-20
Critical: Highly critical
Impact: Security Bypass, Spoofing, Exposure of sensitive information, DoS, System access
Where: From remote
Solution: Update to version 9.52….

:ph34r:
FYI…

Opera v9.60 released
- http://www.opera.com/download/

Changelog:
- http://www.opera.com/docs/changelogs/windows/960/

- http://www.opera.com/support/search/view/901/
# Fixed an issue where specially crafted addresses could execute arbitrary code…

- http://www.opera.com/support/search/view/902/
# Java applets can no longer be used to read sensitive information…

- http://secunia.com/advisories/32177/
Release Date: 2008-10-08
Critical: Highly critical

:ph34r:
FYI…

Opera multiple vulns - update available
- http://secunia.com/advisories/32299/
Release Date: 2008-10-21
Critical: Moderately critical
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch…
The vulnerabilities are reported in versions prior to 9.61.
Solution: Update to version 9.61.
http://www.opera.com/download/ …
Original Advisory:
http://www.opera.com/support/search/view/903/
http://www.opera.com/support/search/view/904/
http://www.opera.com/support/search/view/905/ …

Changelog
- http://www.opera.com/docs/changelogs/windows/961/

:ph34r:
FYI…

Opera 9.62 released
- http://www.opera.com/download/
2008-10-30

Changelog:
- http://www.opera.com/docs/changelogs/windows/962/

- http://www.opera.com/support/search/view/906/
History Search can be used to execute arbitrary code…

- http://www.opera.com/support/search/view/907/
The links panel can allow cross-site scripting…

- http://secunia.com/advisories/32452/
Release Date: 2008-10-30
Critical: Highly critical
Impact: Cross Site Scripting, System access
Where: From remote
Solution Status: Vendor Patch…

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2008-4795
Last revised: 10/31/2008

:ph34r:
FYI…

Opera v9.63 released
- http://www.opera.com/download/
12.17.2008

Changelog:
- http://www.opera.com/docs/changelogs/windows/963/

Security fixes:
- http://www.opera.com/support/search/view/920/
- http://www.opera.com/support/search/view/921/
- http://www.opera.com/support/search/view/922/
- http://www.opera.com/support/search/view/923/
- http://www.opera.com/support/search/view/924/
- SVG images embedded using [image unavailable: image] tags can no longer execute Java or plugin content…
- Opera now imports .p12 private certificates…

- http://secunia.com/advisories/32752

:ph34r: