Opera 10.10 Plugs Extremely and Highly Severe Security Holes
The Opera Software team recently announced the release of Opera 10.10 as a final, stable software application. The most interesting thing about Opera 10.10 is that it has Opera Unite built-in. Thanks to Opera Unite users can turn their computer into a web server; they can for example share photos online or stream music to a mobile phone, game console or anther computer. As CEO Jon von Tetzchner sees it, Opera Unite helps the company deliver its promise to reinvent the web – promise Opera made when it first announced Opera Unite.
“We promised Opera Unite would reinvent the Web. What we are really doing is reinventing how we as consumers interact with the Web. By giving our devices the ability to serve content, we become equal citizens on the Web. In an age where we have ceded control of our personal data to third-parties, Opera Unite gives us the freedom to choose how we will share the data that belongs to us,” commented Jon von Tetzchner.
If Opera Unite is not enough to push you to update to version 10.10, here is something that just might – the 10.10 update fixes a extremely severe and a highly severe security vulnerability. For security reasons at lest, you should update your Opera browser to version 10.10.
The extremely severe vulnerability refers to a heap overflow in string to number conversion. When Opera uses JavaScript to parse very long strings through the string to number conversion, it may lead to heap buffer overflow. Most times this will result in Opera freezing or terminating. In some instances Opera will crash – if someone with malicious intent could get Opera to crash in this manner, then it could lead to remote code execution. Additional techniques will have to be used to inject code though.
The highly severe vulnerability refers to error messages that can leak to unrelated sites. Normally, scripting error messages are available only to the page that caused the error. In some instances these error messages could be passed to other sites – which is an issue if the error messages contain sensitive information. This vulnerability could be used for cross-site scripting. The upside is that the vulnerability only affects installations where stacktraces for exceptions are enabled (they are not enabled by default).
It should be noted that Opera 10.10 also fixes a moderately severe issue uncovered by Google Security Team member Chris Evans. Details on this vulnerability are being withheld for the time being. Opera Software announced it would disclose them “at a later date”.
Tags: Opera Software, Opera 10.10, Opera Unite, Security
“We promised Opera Unite would reinvent the Web. What we are really doing is reinventing how we as consumers interact with the Web. By giving our devices the ability to serve content, we become equal citizens on the Web. In an age where we have ceded control of our personal data to third-parties, Opera Unite gives us the freedom to choose how we will share the data that belongs to us,” commented Jon von Tetzchner.
Advertising
If Opera Unite is not enough to push you to update to version 10.10, here is something that just might – the 10.10 update fixes a extremely severe and a highly severe security vulnerability. For security reasons at lest, you should update your Opera browser to version 10.10.
The extremely severe vulnerability refers to a heap overflow in string to number conversion. When Opera uses JavaScript to parse very long strings through the string to number conversion, it may lead to heap buffer overflow. Most times this will result in Opera freezing or terminating. In some instances Opera will crash – if someone with malicious intent could get Opera to crash in this manner, then it could lead to remote code execution. Additional techniques will have to be used to inject code though.
The highly severe vulnerability refers to error messages that can leak to unrelated sites. Normally, scripting error messages are available only to the page that caused the error. In some instances these error messages could be passed to other sites – which is an issue if the error messages contain sensitive information. This vulnerability could be used for cross-site scripting. The upside is that the vulnerability only affects installations where stacktraces for exceptions are enabled (they are not enabled by default).
It should be noted that Opera 10.10 also fixes a moderately severe issue uncovered by Google Security Team member Chris Evans. Details on this vulnerability are being withheld for the time being. Opera Software announced it would disclose them “at a later date”.
Tags: Opera Software, Opera 10.10, Opera Unite, Security
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 10 Feb 2012
With the release of Wolfram|Alpha Pro, the team behind the popular computational knowledge engine took a very big step forwardBy George Norman on 10 Feb 2012
Microsoft has just announced that this February, as part of the Patch Tuesday program, it will roll out a grand total of 9 security bulletins to all customers all over the world.Related News
By George Norman on 05 Jan 2012
This is proof that there are a lot of threats on the web and the perfect example of why you should use a properly good security solution to secure your data against viruses and other malwareBy George Norman on 17 Nov 2011
We all know that the internet is a dangerous place. There are all sorts of nasties out there, from viruses and worms to scammers and cyber criminals. As a parent, it is your task to make sure that your children stay safe online. This means you have toBy George Norman on 11 Nov 2011
On Thursday, the 10th of November, Norwegian developer Opera Software announced that the Beta version of Opera 11.60 has been released to the public. This version of the Opera web browser carries the codename “Tunny”, which is another name for tuna, a fish known for By George Norman on 28 Nov 2011
Back in August we were reporting that Avast has a grand total of 160 million registered Avast! Free Antivirus Users. Fabricia from Brazil, the 160 millionth user to register the free antivirus product was rewarded withAdvertising
Hot Software Updates
Top Downloads
2.
Opera5.
Trillian8.
AIM9.
Skype10.
Ad-Aware12.
Nero13.
Google Earth14.
Picasa15.
Winamp16.
iTunes17.
RealPlayer18.
uTorrent19.
eMule20.
WinRAR21.
BitComet22.
WinZip23.
Shareaza24.
CCleaner25.
Recuva26.
Tweak UI27.
CuteFTP Home29.
Adobe Reader30.
NewsPiperBecome A Fan!
Link To Us!
Opera 10.10 Plugs Extremely and Highly Severe Security Holes
HTML Linking Code
HTML Linking Code





