This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Opera updates

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Opera v10 released
- http://www.opera.com/browser/
September 01, 2009

What's new in Opera 10
- http://www.opera.com/browser/features/

Security and privacy features
- http://www.opera.com/browser/security/

Changelogs
- http://www.opera.com/docs/changelogs/windows/1000/

> http://secunia.com/advisories/36414/2/
Last Update: 2009-09-04
Critical: Moderately critical
Impact: Spoofing
Where: From remote
Software: Opera 9.x
Solution: Upgrade to version 10.0…
http://www.opera.com/support/kb/view/929/
http://www.opera.com/support/kb/view/930/
http://www.opera.com/support/kb/view/932/
http://www.opera.com/support/kb/view/934/

http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-3047
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-3046
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-3045
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-3044
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-3048
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-3049
FYI…

Opera v10.01 released
- http://secunia.com/advisories/37182/2/
Release Date: 2009-10-28
Critical: Highly critical
Impact: Spoofing, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch
Software: Opera 10.x …
Solution: Update to version 10.01…
Original Advisory:
http://www.opera.com/support/kb/view/938/
http://www.opera.com/support/kb/view/939/
http://www.opera.com/support/kb/view/940/

- http://www.opera.com/browser/download/

:ph34r:
FYI…

Opera v10.10 released
- http://secunia.com/advisories/37469/2/
Release Date: 2009-11-23
Critical: Moderately critical
Impact: Unknown, Cross Site Scripting, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
Software: Opera 10.x …
Solution: Update to version 10.10.
http://www.opera.com/browser/download/ …
Original Advisory:
http://www.opera.com/docs/changelogs/windows/1010/
1) http://www.opera.com/support/kb/view/941/

> http://secunia.com/advisories/37431/2/
Last Update: 2009-11-23
Critical: Highly critical
Solution: Update to version 10.10…
Original Advisory: Opera:
http://www.opera.com/support/kb/view/942/ *
http://www.opera.com/docs/changelogs/windows/1010/
* http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0689
Last revised: 07/01/2009
CVSS v2 Base Score: 6.8 (MEDIUM)
Multiple Vendors libc/gdtoa printf(3) Array Overrun
Hyperlink: http://securityreason.com/achievement_securityalert/63

:ph34r:
FYI…

Opera vuln - workaround available
- http://secunia.com/advisories/38546/2/
Release Date: 2010-02-11
Ciriticality: Less critical
Impact: Manipulation of data
Where: From remote
Solution:
An experimental client side fix is included in Opera 10.50 pre-alpha build 3206.
Software: Opera…
Original Advisory:
http://www.opera.com/docs/changelogs/windows/1050b1/
http://www.opera.com/support/kb/view/944/
http://my.opera.com/securitygroup/blog/201…-tls-renego-fix

:ph34r:
FYI…

Opera exploits publicly available…
- http://isc.sans.org/diary.html?storyid=8356
Last Updated: 2010-03-05 16:03:04 UTC - "Several mailing lists and readers… are reporting publicly available exploits for Opera 10.50 for Windows and below. There actually seems to be at least two different vulnerabilities, both unpatched at this time. One of them seems to be a DoS resulting in a browser crash, but the other looks like it will allow full code execution. The vulnerability finders seem to indicate that these issues are known to exist in previous versions of the Opera also. These are fairly serious and until Opera patches them, you may be well advised to stop using them for the time being."

http://secunia.com/advisories/38820/

http://www.vupen.com/english/advisories/2010/0529

UPDATE: http://secunia.com/advisories/38820/
Comment at bottom of secunia URL…
On its forums, Opera is claiming that the vulnerability is not exploitable and that the report is invalid…
- http://my.opera.com/community/forums/topic.dml?id=442431
"… haavard - Moderator:
Friday, 5. March 2010, 17:41:26 (edited)
… This doesn't seem to be exploitable after being looked into. It might crash, but is there a proof of concept which executes code?"

- http://www.theregister.co.uk/2010/03/05/opera_vulnerability/
5 March 2010 - "A security vulnerability identified in Opera can be exploited to crash users' browsers, but probably can't lead to the remote execution of malware… "We believe that the bug primarily causes a crash, and that exploiting the vulnerability to execute code is extremely difficult, if not impossible," spokesman Thomas Ford told The Register. He went on to say that users should be sure to enable a security feature known as DEP, or data execution prevention. "In our testing, DEP mitigates the problem and should protect the system," he said… DEP isn't always turned on by default… Opera is in the process of pushing out an update that patches the bug."

:ph34r: :ph34r:
FYI…

Opera v10.51 released
- http://www.opera.com/browser/download/?os=….51&local=y
March 22, 2010

Opera 10.51 for Windows changelog
Release notes
- http://www.opera.com/docs/changelogs/windows/1051/
Release date: March 22, 2010
"Opera 10.51 is a recommended security and stability upgrade. Opera highly recommends all users to upgrade to Opera 10.51 to take advantage of these improvements…"

- http://secunia.com/advisories/38820/
Last Update: 2010-03-22
Criticality level: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
Solution: Update to version 10.51…

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2010-1349
Last revised: 04/13/2010
CVSS v2 Base Score: 10.0 (HIGH)

:ph34r:
FYI…

Opera v10.53 released
- http://www.opera.com/docs/changelogs/windows/1053/
April 30, 2010 - Opera 10.53 is a recommended security and stability upgrade…
Changes since Opera 10.52
* Fixed an issue where multiple asynchronous document modifications could be used to execute arbitrary code; see our advisory ( http://www.opera.com/support/search/view/953/ )…

- http://www.opera.com/docs/changelogs/windows/1000/
"… Opera now includes the ability to update itself automatically when new releases become available. By default, Opera will notify the user about available updates. Users can specify…"

- http://secunia.com/advisories/39590/
Solution: Update to version 10.53…

:ph34r:
FYI…

Opera v10.60 released
- http://secunia.com/advisories/40375/
Release Date: 2010-07-01
Criticality level: Moderately critical
Impact: Exposure of system information, Exposure of sensitive information, System access
Where: From remote
… The security issues are reported in versions prior to 10.60.
Solution: Update to version 10.60.
Original Advisory: Opera:
http://www.opera.com/docs/changelogs/windows/1060/
http://www.opera.com/support/kb/view/957/
http://www.opera.com/support/kb/view/958/

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2657
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2658
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2659
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2660
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2661
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2662
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2663
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2664
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2665
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2666

- http://www.opera.com/docs/changelogs/windows/1000/
"… Opera now includes the ability to update itself automatically when new releases become available. By default, Opera will notify the user about available updates…"

:ph34r:
FYI…

Opera v10.61 released
- http://secunia.com/advisories/40120/
Release Date: 2010-08-12
Criticality level: Highly critical
Impact: Security Bypass, System access
Where: From remote
Solution: Update to version 10.61.
Opera:
http://www.opera.com/docs/changelogs/windows/1061/
http://www.opera.com/support/kb/view/966/
http://www.opera.com/support/kb/view/967/
http://www.opera.com/support/kb/view/968/

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2010-3019
Last revised: 08/17/2010 - "… Opera before 10.61…"
CVSS v2 Base Score: 9.3 (HIGH)

:ph34r: :ph34r:
FYI…

Opera v10.62 released
- http://www.opera.com/browser/download/
September 9, 2010

- http://www.opera.com/docs/changelogs/windows/1062/
"Opera 10.62 is a recommended upgrade offering security and stability enhancements…"

Advisory: Malicious DLL files can be unintentionally loaded and allowed to run arbitrary code
- http://www.opera.com/support/kb/view/970/
Severity: High …

- http://secunia.com/advisories/41083/
Last Update: 2010-09-09
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution: Update to version 10.62.

:ph34r:
FYI…

Opera v10.63 released
- http://secunia.com/advisories/41740/
Release Date: 2010-10-12
Criticality level: Highly critical
Impact: Security Bypass, Cross Site Scripting, Spoofing
Where: From remote
Solution: Update to version 10.63…
Original Advisory: Opera:
http://www.opera.com/docs/changelogs/windows/1063/
http://www.opera.com/support/kb/view/971/
http://www.opera.com/support/kb/view/972/
http://www.opera.com/support/kb/view/973/
http://www.opera.com/support/kb/view/974/
http://www.opera.com/support/kb/view/976/

- http://www.securitytracker.com/id?1024570
Oct 13 2010

:ph34r: