Opera Browser "Content-Length" Header Buffer Overflow Vulnerability


Description   A vulnerability has been identified in Opera, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a buffer overflow error when processing malformed HTTP "Content-Length:" headers, which could be exploited by remote attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a web page hosted on a malicious web server.
VUPEN confirmed the vulnerability with Opera version 10.50 on Windows XP SP3.
An error related to the processing of certain XSLT constructs could allow a malicious web page to retrieve contents from arbitrary web sites.
     
Vulnerable Products   Vulnerable Software:
Opera version 10.50 and prior
     
Solution   Upgrade to Opera version 10.51 : http://www.opera.com/browser/download/
     
CVE   CVE-2010-1349
CVE-2010-1310
     
References   http://www.exploit-db.com/exploits/11622
http://www.opera.com/docs/changelogs/windows/1051
http://www.opera.com/support/search/view/948/
http://www.opera.com/support/search/view/949/
     
Vulnerability Manager Detection   Yes (since ASQ v3.5.0)
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Critical 

 Vulnerability First Public Report Date 
2010-03-04 

 Target Type 
Client 

 Possible exploit 
Local & Remote