|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
  CERT-MU Vulnerability Note VN-2010-7

Opera Browser "Content-Length" Processing remote code execution Vulnerability

Original Issue Date: March 10, 2010

Severity Rating: High

Systems Affected

  • Opera version 10.50 and prior

Overview

A buffer overflow vulnerability has been reported in Opera web browser that could be exploited by the remote attacker to execute arbitrary code in the context of logged in user.

Description

The vulnerability is caused when processing HTTP responses having a malformed "Content-Length" header. This can be exploited to cause a heap-based buffer overflow via an overly large 64-bit "Content-Length" value, having the higher 32-bit part negative. An attacker could exploit the vulnerability by constructing a specially crafted Web page containing malformed header an persuading the user to visit the site. Successful exploitation of this vulnerability could allow remote attacker to execute arbitrary code or can crash the affected browser.

Workarounds

Do not browse un-trusted websites or follow un-trusted links.

References

Secunia
http://secunia.com/advisories/38820/

VUPEN
http://www.vupen.com/english/advisories/2010/0529

SecurityFocus
http://www.securityfocus.com/bid/38519/

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

10-Jul-2011