|
|

By John Leyden
Posted: 13/03/2003 at 12:56 GMT
Opera today released a fix for a serious security flaw with its browser which could let crackers load and execute malicious code on victim's PCs.
The vulnerability, which involves both version 6.x and 7.x of the browser, revolves around incorrect handling of very long filenames in the Opera's Download Dialog box.
"This allows a malicious Web site to create a filename that causes a buffer overflow which can be exploited to execute arbitrary code," an advisory by security outfit Secunia explains.
"Exploits are in the wild for Windows," it warns.
A Download Dialog box can be spawned automatically, without user interaction, so the exploit is far more likely to trap unwary users. Secunia describes the risk as "extremely critical", with good reason.
Just as well than that Opera has promptly provided a fix (available here), within a day of the publication of Secunia's alert.
Opera users are strongly urged to upgrade to version 7.03 of the browser.
More @ The Register
|
|
|
 |
| "Advisories!: Opera in fresh browser security drama" | Login/Create an Account | 0 comments |
|
| | The comments are owned by the poster. We aren't responsible for their content. |
|
|
|
No Comments Allowed for Anonymous, please register |
|
| |
|
Login |
|
 |
|
|
|
|
· New User? · Click here to create a registered account.
|
|
|
Article Rating |
|
 |
|
|
|
|
Average Score: 0 Votes: 0
|
|
|