iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > Opera Browser Has JPEG Flaw
Search:
[ news_security_news ]

Opera Browser Has JPEG Flaw



David Utter
Staff Writer
2006-06-23

SecurityProNews: Insider Reports Insider Reports RSS Feed


The 8.54 version of the Opera web browser could be exploited with a newly uncovered vulnerability in how it handles JPEG images.

The vulnerability does not exist in the recently released Opera 9 browser, and the company recommends upgrading to 9 from 8.54. An Opera engineer advised us that it was not likely they would do an incremental upgrade for 8.5x browsers.

If exploited by a maliciously crafted JPEG image, an integer overflow during image processing could lead to a buffer overflow, tracking firm Secunia advised in a statement. That condition could then permit execution of arbitrary code.

The original advisory at VigilantMinds described some more detail about the problem:

If excessively large height and width values are specified in certain fields of a JPEG file, an integer overflow may cause Opera to allocate insufficient memory for the image. This will lead to a buffer overflow when the image is loaded into memory, which can be exploited to execute arbitrary code.

Although upgrading to Opera 9 will eliminate this problem, VigilantMinds still recommends users should access the Internet from machines where limited usage accounts are in use.

---
Tag:

Add to Del.icio.us | Digg | Yahoo! My Web | Furl

Get all the updates in RSS:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds