Opera updates

FYI...

Opera v9.22 released

Download:
- http://www.opera.com/download/index.dml?custom=yes

Changelog for Opera 9.22 for Windows
- http://www.opera.com/docs/changelogs/windows/922/#security

> http://www.opera.com/support/search/view/862/

> http://www.opera.com/support/search/view/863/

> http://www.opera.com/support/search/view/864/

------------

- http://secunia.com/advisories/26138/
Release Date: 2007-07-19
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: Opera 9.x
...The vulnerability is reported in version 9.21 on Windows. Other versions may also be affected...
Solution: Update to version 9.22.
Original Advisory: Opera:
http://www.opera.com/docs/changelogs/windows/922/ ...

.
 
Last edited:
FYI...

- http://secunia.com/advisories/27277/
Last Update: 2007-10-18
Critical: Highly critical
Impact: Cross Site Scripting, System access
Where: From remote
Solution Status: Vendor Patch
Software: Opera 5.x, Opera 6.x, Opera 7.x, Opera 8.x, Opera 9.x
...The vulnerabilities are reported in all versions of Opera for Desktop prior to version 9.24.
Solution: Update to version 9.24.
http://www.opera.com/download/

Changelog for Opera 9.24
> http://www.opera.com/docs/changelogs/windows/924/

- http://www.opera.com/support/search/view/866/

- http://www.opera.com/support/search/view/867/

.
 
Opera v9.25 released

FYI...

Opera v9.25 released
- http://secunia.com/advisories/28169/
Release Date: 2007-12-19
Critical: Highly critical
Impact: Security Bypass, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch...
Solution: Update to version 9.25.

Opera 9.25
- http://www.opera.com/download/

Changelog
- http://www.opera.com/docs/changelogs/windows/925/

Advisory: Rich editing allows cross domain scripting
- http://www.opera.com/support/search/view/875/
"...Opera Software has released Opera 9.25, where this issue has been fixed..."

:fear:
 
Opera v9.26 released

FYI...

Opera v9.26 released
- http://secunia.com/advisories/29029/
Release Date: 2008-02-20
Critical: Moderately critical
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
Software: Opera 5.x, Opera 6.x, Opera 7.x, Opera 8.x, Opera 9.x...
Solution: Update to version 9.26.
> http://www.opera.com/download/

Changelog for Opera 9.26
- http://www.opera.com/docs/changelogs/windows/926/
- Security
> http://www.opera.com/support/search/view/877/
> http://www.opera.com/support/search/view/879/
> http://www.opera.com/support/search/view/880/
- Miscellaneous
* Fixed a stability issue found in Opera 9.0 to 9.25, when Opera connects securely to Windows Server 2008 or other servers supporting the TLS Certificate Status extension.
* Additional stability fixes.
 
FYI...

Opera v9.27 released
- http://www.opera.com/download/
April 3, 2008

Release Notes
- http://www.opera.com/docs/changelogs/windows/927/#security
"This release is a recommended security and stability upgrade..."

- http://www.securityfocus.com/bid/28585/solution
Updated: Apr 12 2008 - "...The vendor released Opera 9.27 to address these issues..."

- http://www.opera.com/support/search/view/881/
- http://www.opera.com/support/search/view/882/

- http://secunia.com/advisories/29662/
Release Date: 2008-04-03
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status:Vendor Patch
...Successful exploitation of the vulnerabilities may allow execution of arbitrary code. The vulnerabilities are reported in versions prior to 9.27.
Solution: Update to version 9.27.

:fear:
 
Last edited:
Opera 9.50 released

FYI...

Opera 9.50 released
- http://www.opera.com/download

- http://www.opera.com/docs/changelogs/windows/950/
"...Opera 9.5 is a recommended security and stability upgrade..."

- http://www.opera.com/docs/changelogs/windows/950/#security
Security:
* Fixed an issue where certain characters could obscure the page address, as reported by Tony Thomas...
* Solved an issue where Images could be read cross-domain with canvas, as reported by Philip Taylor...
* Pages held in frames are no longer able to change the location of pages in unrelated frames on the parent page...
* Improved Fraud Protection now includes advanced malware prevention and upgraded phishing detection technologies...
* Added support for Extended Validation (EV) certificates.
* Added automatic downloading of trusted root certificates when required.
* Disabled SSL v2 and weak ciphers.
* Improvements made to certificate handling, the new certificate repository and the certificates UI.
* Introduced a new security notification scheme in the address field:
o gold lock on green field for secure sites with Extended Validation
o silver lock on yellow field for regular secure sites
o question mark on gray field for HTTPS sites with issues
o no notification for normal sites
o fraud warning on red field for blacklisted sites
* Opera now distinguishes between local servers on localhost, intranet servers, and remote servers on the Internet.
o Local servers can use remote resources, but not vice versa...

- http://secunia.com/advisories/30636/
Release Date: 2008-06-12
Critical: Less critical
Impact: Spoofing, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
...The vulnerabilities are reported in versions prior to 9.5...
Solution: Update to version 9.5...
http://www.opera.com/download/

:fear:
 
Last edited:
Opera 9.51 released

FYI...

Opera 9.51 released
- http://www.opera.com/download/
03.07.2008

Release Notes:
- http://www.opera.com/docs/changelogs/windows/951/#security
"Opera 9.51 is a recommended security and stability upgrade...
Miscellaneous
* Corrected a stability issue with Yahoo! Mail.
* TinyMCE 2.1.x editor now works properly.
* Printing of chat items has been improved.
* Reconnection of the IRC client has been adjusted and improved.
* Menus on deviantart.com now work properly.
* Eliminated unwanted line breaks in rich text editors.
Windows-specific changes
* Fixed a resource leak in the transfer window that could cause visual paint problems and other related problems.
* Command line parameters must now be specified before any URLs on the command line...

- http://www.opera.com/support/search/view/887/

- http://secunia.com/advisories/30937/
Release Date: 2008-07-03
Critical: Highly critical...

:fear:
 
Opera 9.52 released

FYI...

Opera 9.52 released
- http://www.opera.com/download/

Changelog
- http://www.opera.com/docs/changelogs/windows/952/
Opera 9.52 is a recommended security and stability upgrade...

Security advisories:
- http://www.opera.com/support/search/view/892/
- http://www.opera.com/support/search/view/893/
- http://www.opera.com/support/search/view/894/
- http://www.opera.com/support/search/view/895/
- http://www.opera.com/support/search/view/896/
- http://www.opera.com/support/search/view/897/

- http://secunia.com/advisories/31549/
Release Date: 2008-08-20
Critical: Highly critical
Impact: Security Bypass, Spoofing, Exposure of sensitive information, DoS, System access
Where: From remote
Solution: Update to version 9.52....

:fear:
 
Last edited:
Opera multiple vulns - update available

FYI...

Opera multiple vulns - update available
- http://secunia.com/advisories/32299/
Release Date: 2008-10-21
Critical: Moderately critical
Impact: Security Bypass, Cross Site Scripting, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch...
The vulnerabilities are reported in versions prior to 9.61.
Solution: Update to version 9.61.
http://www.opera.com/download/ ...
Original Advisory:
http://www.opera.com/support/search/view/903/
http://www.opera.com/support/search/view/904/
http://www.opera.com/support/search/view/905/ ...

Changelog
- http://www.opera.com/docs/changelogs/windows/961/

:fear:
 
Last edited:
Opera v9.62 released

FYI...

Opera v9.62 released
- http://www.opera.com/download/
2008-10-30

Changelog:
- http://www.opera.com/docs/changelogs/windows/962/

- http://www.opera.com/support/search/view/906/
History Search can be used to execute arbitrary code...

- http://www.opera.com/support/search/view/907/
The links panel can allow cross-site scripting...

- http://secunia.com/advisories/32452/
Release Date: 2008-10-30
Critical: Highly critical
Impact: Cross Site Scripting, System access
Where: From remote
Solution Status: Vendor Patch...

- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4795
Last revised: 10/31/2008

:fear:
 
Last edited:
FYI...

Opera v9.63 released
- http://www.opera.com/download/
12.17.2008

Changelog:
- http://www.opera.com/docs/changelogs/windows/963/

Security fixes:
- http://www.opera.com/support/search/view/920/
- http://www.opera.com/support/search/view/921/
- http://www.opera.com/support/search/view/922/
- http://www.opera.com/support/search/view/923/
- http://www.opera.com/support/search/view/924/
- SVG images embedded using <img> tags can no longer execute Java or plugin content...
- Opera now imports .p12 private certificates...

- http://secunia.com/advisories/32752

:fear:
 
Last edited:
Opera v10.01 released

FYI...

Opera v10.01 released
- http://secunia.com/advisories/37182/2/
Release Date: 2009-10-28
Critical: Highly critical
Impact: Spoofing, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch
Software: Opera 10.x ...
Solution: Update to version 10.01...
Original Advisory:
http://www.opera.com/support/kb/view/938/
http://www.opera.com/support/kb/view/939/
http://www.opera.com/support/kb/view/940/

- http://www.opera.com/browser/download/

:fear:
 
Opera v10.10 released

FYI...

Opera v10.10 released
- http://secunia.com/advisories/37469/2/
Release Date: 2009-11-23
Critical: Moderately critical
Impact: Unknown, Cross Site Scripting, Exposure of sensitive information
Where: From remote
Solution Status: Vendor Patch
Software: Opera 10.x ...
Solution: Update to version 10.10.
http://www.opera.com/browser/download/ ...
Original Advisory:
http://www.opera.com/docs/changelogs/windows/1010/
1) http://www.opera.com/support/kb/view/941/

> http://secunia.com/advisories/37431/2/
Last Update: 2009-11-23
Critical: Highly critical
Solution: Update to version 10.10...
Original Advisory: Opera:
http://www.opera.com/support/kb/view/942/ *
http://www.opera.com/docs/changelogs/windows/1010/
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0689
Last revised: 07/01/2009
CVSS v2 Base Score: 6.8 (MEDIUM)
Multiple Vendors libc/gdtoa printf(3) Array Overrun
Hyperlink: http://securityreason.com/achievement_securityalert/63

:fear:
 
Last edited:
Opera vuln - workaround available

FYI...

Opera vuln - workaround available
- http://secunia.com/advisories/38546/2/
Release Date: 2010-02-11
Ciriticality: Less critical
Impact: Manipulation of data
Where: From remote
Solution:
An experimental client side fix is included in Opera 10.50 pre-alpha build 3206.
Software: Opera...
Original Advisory:
http://www.opera.com/docs/changelogs/windows/1050b1/
http://www.opera.com/support/kb/view/944/
http://my.opera.com/securitygroup/blog/2010/01/23/alpha-testing-tls-renego-fix

:fear:
 
Last edited:
Back
Top