Featured Worklog

Price Search



PC Apex Sponsor


PC Apex Sponsors



PC Apex RSS Feeds

RSS Feed for PC Apex Reviews & ArticlesRSS Feed for PC Apex PC Modding WorklogsRSS Feed for the PC Apex Daily DisturbanceRSS Feed for the latest PC Apex Site NewsRSS Feed for PC Apex Affiliate and Web NewsRSS Feed for PC Apex Deals and Steals

Go Back   Apex Community Forums // PC Apex Forums // PC Apex RSS News Feeds // Slashdot RSS

Slashdot RSS RSS news feed directly from Slashdot.

Reply
 
LinkBack Thread Tools Display Modes
Old 06-January-07, 02:30 PM   #1 (permalink)
News Hound
Gizmo's Avatar
Default Slashdot // Opera Security Patched In Secret

An anonymous reader writes "Opera 9.10 released in December seemed to be a rather cosmetic update. But as heise Security reports, behind the scenes Opera patched two remote code execution holes — neither of them mentioned in the changelog. In addition, Opera rates an exploitable heap overflow as 'moderate' because it is 'not trivial to exploit it reliably'. From the article: 'JPEG images can be specially prepared to cause a buffer overflow on the heap. Even though Opera suggests in the heading to its security notice that this problem only causes the browser to crash, the flaw can nonetheless be exploited to inject and execute code. Security service provider iDefense, which reported the hole to Opera, has confirmed this. The same holds true for a flawed type conversion in the JavaScript support for Scalable Vector Graphics (SVG). Attackers can specially call the function createSVGTransformFromMatrix to have the browser execute code with the user's rights.'"



More...
Gizmo is offline     Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Slashdot // Gaping Holes In Fully Patched IE7, Firefox 2 Gizmo Slashdot RSS 0 05-June-07 01:20 AM
The Register // Civil Aviation Authority puts 'secret' security info on the web Gizmo The Register RSS 0 02-November-06 08:29 PM
The Register // Secret court secretly reviewing secret wiretaps Gizmo The Register RSS 0 14-July-06 04:01 PM
The Register // Ssshhh! Opera slips out security update Gizmo The Register RSS 0 18-June-05 02:22 PM
Opera in minor security drama Lokie PC Apex Web News 0 22-October-03 07:22 PM


All times are GMT -5. The time now is 04:21 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC5
Copyright PCApex.com, GameApex.com, ForumApex.com 2001 - 2008
Advertisements

Page generated in 0.10958 seconds with 9 queries