Opera: Multiple vulnerabilities

Security Team  Contact Address

Updated November 03, 2008

1.  Gentoo Linux Security Advisory

Version Information

Advisory Reference GLSA 200811-01 / opera
Release Date November 03, 2008
Latest Revision November 03, 2008: 01
Impact normal
Exploitable remote
Package Vulnerable versions Unaffected versions Architecture(s)
www-client/opera < 9.62 >= 9.62 All supported architectures

Related bugreports: #235298, #240500, #243060, #244980

Synopsis

Multiple vulnerabilities have been discovered in Opera, allowing for the execution of arbitrary code.

2.  Impact Information

Background

Opera is a fast web browser that is available free of charge.

Description

Multiple vulnerabilities have been discovered in Opera:

Impact

These vulnerabilties allow remote attackers to execute arbitrary code, to run scripts injected into Opera's History Search with elevated privileges, to inject arbitrary web script or HTML into web pages, to manipulate the address bar, to change Opera's preferences, to determine the validity of local filenames, to read cache files, browsing history, and subscribed feeds or to conduct other attacks.

3.  Resolution Information

Workaround

There is no known workaround at this time.

Resolution

All Opera users should upgrade to the latest version:

Code Listing 3.1: Resolution

# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/opera-9.62"

4.  References