Opera: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200804-14 / opera |
| Release Date |
April 14, 2008 |
| Latest Revision |
April 14, 2008: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-client/opera |
<
9.27 |
>=
9.27 |
All supported architectures
|
Related bugreports:
#216022
Synopsis
Multiple vulnerabilities have been discovered in Opera, allowing for
execution of arbitrary code.
2.
Impact Information
Background
Opera is a fast web browser that is available free of charge.
Description
Michal Zalewski reported two vulnerabilities, memory corruption when
adding news feed sources from a website (CVE-2008-1761) as well as when
processing HTML CANVAS elements to use scaled images (CVE-2008-1762).
Additionally, an unspecified weakness related to keyboard handling of
password inputs has been reported (CVE-2008-1764).
Impact
A remote attacker could entice a user to visit a specially crafted web
site or news feed and possibly execute arbitrary code with the
privileges of the user running Opera.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Opera users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/opera-9.27"
|
4.
References
|