Original URL: https://www.theregister.com/2005/06/17/opera_security_update/

Ssshhh! Opera slips out security update

No big drama over JavaScript bug

By John Leyden

Posted in Channel, 17th June 2005 14:28 GMT

Opera users are urged to update their browser software following the discovery of a security flaw that creates a means for hackers to read local files using a form of cross-site scripting attack.

The vulnerability stems from a failure by Opera to restrict JavaScript privileges, for example, when "javascript:" URLs are opened in new windows or frames. The vulnerability has been confirmed in Opera version 8.0. Other versions may also be affected. Security alerting firm Secunia, which discovered the bug, describes the vulnerability as "moderately critical". Users of the popular alternative browser software are urged to update to version 8.01 of Opera for Windows and Linux, released on Thursday (16 June). ®

Related stories

Opera beefs up browser to thwart phishers
Firefox dusted down with security upgrade
A fright at the Opera
Drive-by Trojans exploit browser flaws
10 vulns - three critical - in MS patch batch