Opera updates

Opera exploits publicly available

FYI...

Opera exploits publicly available...
- http://isc.sans.org/diary.html?storyid=8356
Last Updated: 2010-03-05 16:03:04 UTC - "Several mailing lists and readers... are reporting publicly available exploits for Opera 10.50 for Windows and below. There actually seems to be at least two different vulnerabilities, both unpatched at this time. One of them seems to be a DoS resulting in a browser crash, but the other looks like it will allow full code execution. The vulnerability finders seem to indicate that these issues are known to exist in previous versions of the Opera also. These are fairly serious and until Opera patches them, you may be well advised to stop using them for the time being."

http://secunia.com/advisories/38820/

http://www.vupen.com/english/advisories/2010/0529

UPDATE: http://secunia.com/advisories/38820/
Comment at bottom of secunia URL...
On its forums, Opera is claiming that the vulnerability is not exploitable and that the report is invalid...
- http://my.opera.com/community/forums/topic.dml?id=442431
"... haavard - Moderator:
Friday, 5. March 2010, 17:41:26 (edited)
... This doesn't seem to be exploitable after being looked into. It might crash, but is there a proof of concept which executes code?"

- http://www.theregister.co.uk/2010/03/05/opera_vulnerability/
5 March 2010 - "A security vulnerability identified in Opera can be exploited to crash users' browsers, but probably can't lead to the remote execution of malware... "We believe that the bug primarily causes a crash, and that exploiting the vulnerability to execute code is extremely difficult, if not impossible," spokesman Thomas Ford told The Register. He went on to say that users should be sure to enable a security feature known as DEP, or data execution prevention. "In our testing, DEP mitigates the problem and should protect the system," he said... DEP isn't always turned on by default... Opera is in the process of pushing out an update that patches the bug."

:fear::fear:
 
Last edited:
Opera v10.51 released

FYI...

Opera v10.51 released
- http://www.opera.com/browser/download/?os=windows&ver=10.51&local=y
March 22, 2010

Opera 10.51 for Windows changelog
Release notes
- http://www.opera.com/docs/changelogs/windows/1051/
Release date: March 22, 2010
"Opera 10.51 is a recommended security and stability upgrade. Opera highly recommends all users to upgrade to Opera 10.51 to take advantage of these improvements..."

- http://secunia.com/advisories/38820/
Last Update: 2010-03-22
Criticality level: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
Solution: Update to version 10.51...

- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1349
Last revised: 04/13/2010
CVSS v2 Base Score: 10.0 (HIGH)

:fear:
 
Last edited:
Opera v10.53 released

FYI...

Opera v10.53 released
- http://www.opera.com/docs/changelogs/windows/1053/
April 30, 2010 - Opera 10.53 is a recommended security and stability upgrade...
Changes since Opera 10.52
* Fixed an issue where multiple asynchronous document modifications could be used to execute arbitrary code; see our advisory ( http://www.opera.com/support/search/view/953/ )...

- http://www.opera.com/docs/changelogs/windows/1000/
"... Opera now includes the ability to update itself automatically when new releases become available. By default, Opera will notify the user about available updates. Users can specify..."

- http://secunia.com/advisories/39590/
Solution: Update to version 10.53...

:fear:
 
Opera v10.60 released

FYI...

Opera v10.60 released
- http://secunia.com/advisories/40375/
Release Date: 2010-07-01
Criticality level: Moderately critical
Impact: Exposure of system information, Exposure of sensitive information, System access
Where: From remote
... The security issues are reported in versions prior to 10.60.
Solution: Update to version 10.60.
Original Advisory: Opera:
http://www.opera.com/docs/changelogs/windows/1060/
http://www.opera.com/support/kb/view/957/
http://www.opera.com/support/kb/view/958/

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2657
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2658
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2659
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2660
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2661
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2662
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2663
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2664
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2665
- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2666

- http://www.opera.com/docs/changelogs/windows/1000/
"... Opera now includes the ability to update itself automatically when new releases become available. By default, Opera will notify the user about available updates..."

:fear:
 
Last edited:
Opera v10.61 released

FYI...

Opera v10.61 released
- http://secunia.com/advisories/40120/
Release Date: 2010-08-12
Criticality level: Highly critical
Impact: Security Bypass, System access
Where: From remote
Solution: Update to version 10.61.
Opera:
http://www.opera.com/docs/changelogs/windows/1061/
http://www.opera.com/support/kb/view/966/
http://www.opera.com/support/kb/view/967/
http://www.opera.com/support/kb/view/968/

- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3019
Last revised: 08/17/2010 - "... Opera before 10.61..."
CVSS v2 Base Score: 9.3 (HIGH)

:fear::fear:
 
Last edited:
Opera v10.62 released

FYI...

Opera v10.62 released
- http://www.opera.com/browser/download/
September 9, 2010

- http://www.opera.com/docs/changelogs/windows/1062/
"Opera 10.62 is a recommended upgrade offering security and stability enhancements..."

Advisory: Malicious DLL files can be unintentionally loaded and allowed to run arbitrary code
- http://www.opera.com/support/kb/view/970/
Severity: High ...

- http://secunia.com/advisories/41083/
Last Update: 2010-09-09
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution: Update to version 10.62.

:fear:
 
Opera v10.63 released

FYI...

Opera v10.63 released
- http://secunia.com/advisories/41740/
Release Date: 2010-10-12
Criticality level: Highly critical
Impact: Security Bypass, Cross Site Scripting, Spoofing
Where: From remote
Solution: Update to version 10.63...
Original Advisory: Opera:
http://www.opera.com/docs/changelogs/windows/1063/
http://www.opera.com/support/kb/view/971/
http://www.opera.com/support/kb/view/972/
http://www.opera.com/support/kb/view/973/
http://www.opera.com/support/kb/view/974/
http://www.opera.com/support/kb/view/976/

- http://www.securitytracker.com/id?1024570
Oct 13 2010

:fear:
 
Last edited:
Opera v11.00 released

FYI...

Opera v11.00 released
- http://www.opera.com/browser/download/
Dec 16 2010

Changelog
- http://www.opera.com/docs/changelogs/windows/1100/
"Opera 11.00 is a recommended upgrade offering new and improved features, plus security and stability enhancements...
Security - Fixed:
• Fixed an issue where Web page content could display misleading security information; see our advisory:
- http://www.opera.com/support/search/view/977/
• Fixed an issue which could allow leaking of WAP form content to other sites; see our advisory:
- http://www.opera.com/support/search/view/979/
• Fixed a high severity issue; details will be disclosed at a later date.
• Fixed further high severity issues; details will be disclosed at a later date..."

- http://secunia.com/advisories/42653/
Release Date: 2010-12-16
Criticality level: Moderately critical
Impact: Unknown, Manipulation of data, Exposure of sensitive information
Where: From remote...
Solution: Upgrade to version 11.00.
Original Advisory: Opera:
http://www.opera.com/docs/changelogs/unix/1100/
http://www.opera.com/support/kb/view/977/
http://www.opera.com/support/kb/view/979/

- http://www.securitytracker.com/id?1024909
Dec 17 2010

:fear:
 
Last edited:
Opera v11.01 released

FYI...

Opera v11.01 released
- http://www.opera.com/browser/download/
January 27, 2011

Release notes
- http://www.opera.com/docs/changelogs/windows/1101/
"Opera 11.01 is a recommended upgrade offering security and stability enhancements..."

- http://secunia.com/advisories/43023/
Last Update: 2011-01-27
Criticality level: Highly critical
Impact: Security Bypass, Exposure of sensitive information, System access
Where: From remote
Solution Status: Vendor Patch ...
Original Advisory: Opera:
1) http://www.opera.com/support/kb/view/982/
2) http://www.opera.com/support/kb/view/983/
3) http://www.opera.com/support/kb/view/984/
4) http://www.opera.com/support/kb/view/985/
5) http://www.opera.com/support/kb/view/986/

- http://www.securitytracker.com/id/1025011
Jan 28 2011

:fear:
 
Last edited:
Opera v11.50 released

FYI...

Opera v11.50 released
- http://www.opera.com/browser/download/?custom=yes
June 28, 2011

- http://www.opera.com/docs/changelogs/windows/1150/
"... recommended upgrade offering new and improved features, plus security and stability enhancements..."
Severity: High: http://www.opera.com/support/kb/view/995/

- http://www.opera.com/support/kb/view/996/
___

- http://www.securitytracker.com/id/1025735
Jun 29 2011
... prior to 11.50
Description: ... A remote user can cause denial of service conditions... conduct cross-site scripting attacks...
Solution: The vendor has issued a fix (11.50)...

- http://secunia.com/advisories/45060/
Release Date: 2011-06-29
Criticality level: Moderately critical
Impact: Unknown, Security Bypass
Where: From remote
Solution: Update to version 11.50...

:fear:
 
Last edited:
Opera v11.51 released

FYI...

Opera v11.51 released
- http://www.opera.com/browser/download/
August 31, 2011

Release notes
- http://www.opera.com/docs/changelogs/windows/1151/
"Opera 11.51 is a recommended upgrade offering security and stability enhancements."

- http://www.opera.com/support/kb/view/1000/

- http://my.opera.com/securitygroup/blog/2011/08/30/when-certificate-authorities-are-hacked-2
30. August 2011
___

- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3389
Last revised: 09/09/2011
"... before 11.51..."
CVSS v2 Base Score: 10.0 (HIGH)

- https://secunia.com/advisories/45791/
Release Date: 2011-08-31
Criticality level: Moderately critical
Impact: Unknown, Security Bypass
Where: From remote
Solution: Update to version 11.51.

- http://www.securitytracker.com/id/1025997
Sep 1 2011

:fear:
 
Last edited:
Opera v11.52 released

FYI...

Opera v11.52 released
- http://www.opera.com/browser/download/
19 October 2011

- http://www.opera.com/docs/changelogs/windows/1152/
"... security and stability enhancements."

- http://www.opera.com/support/kb/view/1002/
"... embedded SVG image can cause Opera to crash..."
[Fixed in 11.52]

- https://secunia.com/advisories/46375/
Last Update: 2011-10-19
Criticality level: Highly critical
Impact: System access
Where: From remote
... vulnerability is confirmed in version 11.51 Build 1087. Other versions may also be affected.
Solution: Update to version 11.52.

- http://h-online.com/-1363825
19 October 2011

:fear:
 
Back
Top