===================================================================== CERT-Renater Note d'Information No. 2008/VULN409 _____________________________________________________________________ DATE : 08/10/2008 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Systems running Opera versions prior to 9.6. ====================================================================== http://www.opera.com/support/search/view/901/ http://www.opera.com/support/search/view/902/ ______________________________________________________________________ Advisory: Specially crafted addresses can execute arbitrary code Severity: Extremely Severe Problem Description If a malicious page redirects Opera to a specially crafted address (URL), it can cause Opera to crash. Given sufficient address content, the crash could cause execution of code controlled by the attacking page. Opera's Response Opera Software has released Opera 9.60, where this issue has been fixed. Credits Thanks to Chris of Matasano Security for reporting this issue to Opera Software. ________________________________________________________________________ Advisory: Java applets can be used to read sensitive information Severity: Highly Severe Problem Description Once a Java applet has been cached, if a page can predict the cache path for that applet, it can load the applet from the cache, causing it to run in the context of the local machine. This allows it to read other cache files on the computer or perform other normally more restrictive actions. These files could contain sensitive information, which could then be sent to the attacker. Opera's Response Opera Software has released Opera 9.60, where this issue has been fixed. Credits Thanks to Nate McFeters for reporting this issue to Opera Software. ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================