Opera exploits publicly available…
- http://isc.sans.org/diary.html?storyid=8356
Last Updated: 2010-03-05 16:03:04 UTC - "Several mailing lists and readers… are reporting publicly available exploits for Opera 10.50 for Windows and below. There actually seems to be at least two different vulnerabilities, both unpatched at this time. One of them seems to be a DoS resulting in a browser crash, but the other looks like it will allow full code execution. The vulnerability finders seem to indicate that these issues are known to exist in previous versions of the Opera also. These are fairly serious and until Opera patches them, you may be well advised to stop using them for the time being."
UPDATE: http://secunia.com/advisories/38820/
Comment at bottom of secunia URL…
On its forums, Opera is claiming that the vulnerability is not exploitable and that the report is invalid…
- http://my.opera.com/community/forums/topic.dml?id=442431
"… haavard - Moderator:
Friday, 5. March 2010, 17:41:26 (edited)
… This doesn't seem to be exploitable after being looked into. It might crash, but is there a proof of concept which executes code?"
- http://www.theregister.co.uk/2010/03/05/opera_vulnerability/
5 March 2010 - "A security vulnerability identified in Opera can be exploited to crash users' browsers, but probably can't lead to the remote execution of malware… "We believe that the bug primarily causes a crash, and that exploiting the vulnerability to execute code is extremely difficult, if not impossible," spokesman Thomas Ford told The Register. He went on to say that users should be sure to enable a security feature known as DEP, or data execution prevention. "In our testing, DEP mitigates the problem and should protect the system," he said… DEP isn't always turned on by default… Opera is in the process of pushing out an update that patches the bug."
Opera 10.51 for Windows changelog
Release notes
- http://www.opera.com/docs/changelogs/windows/1051/
Release date: March 22, 2010
"Opera 10.51 is a recommended security and stability upgrade. Opera highly recommends all users to upgrade to Opera 10.51 to take advantage of these improvements…"
- http://secunia.com/advisories/38820/
Last Update: 2010-03-22
Criticality level: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
Solution: Update to version 10.51…
- http://www.opera.com/docs/changelogs/windows/1052/
"Opera 10.52 is a recommended stability upgrade. Opera highly recommends all users to upgrade to this version to take advantage of these improvements…"
(Many fixes listed 'since Opera 10.51')
- http://www.opera.com/docs/changelogs/windows/1000/
"… Opera now includes the ability to update itself automatically when new releases become available. By default, Opera will notify the user about available updates. Users can specify…"
- http://www.opera.com/docs/changelogs/windows/1000/
"… Opera now includes the ability to update itself automatically when new releases become available. By default, Opera will notify the user about available updates…"
- http://secunia.com/advisories/41083/
Last Update: 2010-09-09
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution: Update to version 10.62.