PDA

View Full Version : Opera Browser BitTorrent Header Parsing Remote Code Execution Vulnerability


xcdegasp
22-07-2007, 19:34
Rated as : High Risk
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-07-20

A vulnerability has been identified in Opera, which could be exploited by attackers to execute arbitrary code. This issue is caused by an error when parsing a specially crafted BitTorrent header, which could be exploited by attackers to cause a vulnerable browser to use memory that has already been freed, resulting in an invalid object pointer being dereferenced when a user right clicks on the transfer and removes it.


Affected Products:
Opera versions prior to 9.22

Solution:
Upgrade to Opera version 9.22 :
http://www.opera.com/download/


Fonte: http://www.frsirt.com/english/advisories/2007/2584

c.m.g
22-07-2007, 20:07
Solution:
Upgrade to Opera version 9.22 :
http://www.opera.com/download/


Fonte: http://www.frsirt.com/english/advisories/2007/2584

già fatto :read: :D

comunque grazie per l'info, in effetti non sapevo il perchè di questo upgrade. ;)

sampei.nihira
22-07-2007, 20:49
Grazie.
Ho aggiornato adesso con la funzione "ricerca aggiornamenti"....anche se non uso mai il bitTorrent.....

FOXYLADY
22-07-2007, 22:11
Grazie :)
Aggiornato anche io alla 9.22.