Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200701-08 ] Opera: Two remote code execution vulnerabilities
Date: Fri, 12 Jan 2007 21:56:28
Message-Id: 20070112211903.GS23772@falco.falcal.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200701-08
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Opera: Two remote code execution vulnerabilities
9 Date: January 12, 2007
10 Bugs: #160369
11 ID: 200701-08
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Two vulnerabilities may allow the execution of arbitrary code.
19
20 Background
21 ==========
22
23 Opera is a multi-platform web browser.
24
25 Affected packages
26 =================
27
28 -------------------------------------------------------------------
29 Package / Vulnerable / Unaffected
30 -------------------------------------------------------------------
31 1 www-client/opera < 9.10 >= 9.10
32
33 Description
34 ===========
35
36 Christoph Deal discovered that JPEG files with a specially crafted DHT
37 marker can be exploited to cause a heap overflow. Furthermore, an
38 anonymous person discovered that Opera does not correctly handle
39 objects passed to the "createSVGTransformFromMatrix()" function.
40
41 Impact
42 ======
43
44 An attacker could potentially exploit the vulnerabilities to execute
45 arbitrary code with the privileges of the user running Opera by
46 enticing a victim to open a specially crafted JPEG file or a website
47 containing malicious JavaScript code.
48
49 Workaround
50 ==========
51
52 The vendor recommends disabling JavaScript to avoid the
53 "createSVGTransformFromMatrix" vulnerability. There is no known
54 workaround for the other vulnerability.
55
56 Resolution
57 ==========
58
59 All Opera users should update to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=www-client/opera-9.10"
63
64 References
65 ==========
66
67 [ 1 ] Opera Advisory (createSVGTransformFromMatrix)
68 http://www.opera.com/support/search/supsearch.dml?index=851
69 [ 2 ] Opera Advisory (JPEG)
70 http://www.opera.com/support/search/supsearch.dml?index=852
71 [ 3 ] CVE-2007-0126
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0126
73 [ 4 ] CVE-2007-0127
74 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0127
75
76 Availability
77 ============
78
79 This GLSA and any updates to it are available for viewing at
80 the Gentoo Security Website:
81
82 http://security.gentoo.org/glsa/glsa-200701-08.xml
83
84 Concerns?
85 =========
86
87 Security is a primary focus of Gentoo Linux and ensuring the
88 confidentiality and security of our users machines is of utmost
89 importance to us. Any security concerns should be addressed to
90 security@g.o or alternatively, you may file a bug at
91 http://bugs.gentoo.org.
92
93 License
94 =======
95
96 Copyright 2007 Gentoo Foundation, Inc; referenced text
97 belongs to its owner(s).
98
99 The contents of this document are licensed under the
100 Creative Commons - Attribution / Share Alike license.
101
102 http://creativecommons.org/licenses/by-sa/2.5