Feeds

Phantom of the Opera

Five vulns, three serious in Opera 7

  • alert
  • submit to reddit

The essential guide to IT transformation

Opera is racing to fix five vulnerabilities, three of which are said to be serious, involving the latest version of its popular Web browsing software.

Israeli security outfit GreyMagic Software today published five security advisories, largely related to Opera 7's JavaScript Console feature.

The three most severe vulnerabilities (here, here and here) might allow full read access to the user's file system, including the ability to list contents of directories, read files, access emails and more, GreyMagic says.

Previous versions of Opera are not subject to these flaws nor to two less severe vulnerabilities (here and here). These disclose previous sites visited by an Opera user to other sites he or she visits.

Although patches are yet to be made available there are workarounds to address all five vulnerabilities. Four of the bugs can be quashed by disabling JavaScript, according to GreyMagic, while the fifth can be addressed by making manual changes to Opera 7's JavaScript console explained in an advisory here (look under 'solution').

Opera has a good security record. Vulnerabilities in its software are rare, though not unprecendented. It is taking the security issues highlighted by Grey Magic seriously.

"Our engineers and QA department have worked hard over the weekend to plug all holes. A new version is in the pipeline for release tonight or tomorrow morning," a representative of Opera told us.

Opera criticises GreyMagic for releasing its advisories too early.

"Unfortunately our request to GreyMagic to delay releasing the report until Thursday was denied, making it impossible for us to come out with a new version of release quality quickly enough to avoid our users from being worried."

According to Opera, GreyMagic only notified it of problems with Opera 7 on Friday afternoon (January 31).

GreyMagic confirms this and says it released its advisories to try to alert people that it might be wise to hold off on downloading Opera 7 until the bugs have been fixed.

Alternatively those who're already using Opera 7 can be made aware of possible risks and workarounds through its advisory, GreyMagic argues. ®

Related Stories

Opera releases version 7 of the 'other' browser
A fright at the Opera

External Links

List of GreyMagic's Opera advisories (which include proof of concept demonstrations)

5 things you didn’t know about cloud backup

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
KER-CHING! CryptoWall ransomware scam rakes in $1 MEEELLION
Anatomy of the net's most destructive ransomware threat
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Gartner critical capabilities for enterprise endpoint backup
Learn why inSync received the highest overall rating from Druva and is the top choice for the mobile workforce.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.