Opera: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201209-11 / opera |
| Release Date |
September 25, 2012 |
| Latest Revision |
September 25, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-client/opera |
<
12.01.1532 |
>=
12.01.1532 |
All supported architectures
|
Related bugreports:
#429478, #434584
Synopsis
Multiple vulnerabilities have been found in Opera, the worst of
which may allow remote execution of arbitrary code.
2.
Impact Information
Background
Opera is a fast web browser that is available free of charge.
Description
Multiple vulnerabilities have been discovered in Opera. Please review
the CVE identifiers and Opera Release Notes referenced below for details.
Impact
A remote attacker could entice a user to open a specially crafted web
page using Opera, possibly resulting in execution of arbitrary code with
the privileges of the process or a Denial of Service condition.
Furthermore, a remote attacker may be able to trick a user into
downloading and executing files, conduct Cross-Site Scripting (XSS)
attacks, spoof the address bar, or have other unspecified impact.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Opera users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-client/opera-12.01.1532"
|
4.
References
|