Feeds

Phantom of the Opera

Five vulns, three serious in Opera 7

  • alert
  • submit to reddit

Remote control for virtualized desktops

Opera is racing to fix five vulnerabilities, three of which are said to be serious, involving the latest version of its popular Web browsing software.

Israeli security outfit GreyMagic Software today published five security advisories, largely related to Opera 7's JavaScript Console feature.

The three most severe vulnerabilities (here, here and here) might allow full read access to the user's file system, including the ability to list contents of directories, read files, access emails and more, GreyMagic says.

Previous versions of Opera are not subject to these flaws nor to two less severe vulnerabilities (here and here). These disclose previous sites visited by an Opera user to other sites he or she visits.

Although patches are yet to be made available there are workarounds to address all five vulnerabilities. Four of the bugs can be quashed by disabling JavaScript, according to GreyMagic, while the fifth can be addressed by making manual changes to Opera 7's JavaScript console explained in an advisory here (look under 'solution').

Opera has a good security record. Vulnerabilities in its software are rare, though not unprecendented. It is taking the security issues highlighted by Grey Magic seriously.

"Our engineers and QA department have worked hard over the weekend to plug all holes. A new version is in the pipeline for release tonight or tomorrow morning," a representative of Opera told us.

Opera criticises GreyMagic for releasing its advisories too early.

"Unfortunately our request to GreyMagic to delay releasing the report until Thursday was denied, making it impossible for us to come out with a new version of release quality quickly enough to avoid our users from being worried."

According to Opera, GreyMagic only notified it of problems with Opera 7 on Friday afternoon (January 31).

GreyMagic confirms this and says it released its advisories to try to alert people that it might be wise to hold off on downloading Opera 7 until the bugs have been fixed.

Alternatively those who're already using Opera 7 can be made aware of possible risks and workarounds through its advisory, GreyMagic argues. ®

Related Stories

Opera releases version 7 of the 'other' browser
A fright at the Opera

External Links

List of GreyMagic's Opera advisories (which include proof of concept demonstrations)

Intelligent flash storage arrays

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.