[27888] in bugtraq

home help back first fref pref prev next nref lref last post

Opera 7 vulnerabilities

daemon@ATHENA.MIT.EDU (GreyMagic Software)
Fri Nov 15 23:12:45 2002

From: "GreyMagic Software" <security@greymagic.com>
To: "Bugtraq" <bugtraq@securityfocus.com>
Date: Thu, 14 Nov 2002 18:43:02 +0200
Message-ID: <LPBBLDGNEFOGMGAEHJPBCEEGDBAA.security@greymagic.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

We've done some basic security tests, in cooperation with Tom Gilder, on the
new Opera 7 beta release and found two major security vulnerabilities. These
vulnerabilities are quite obvious and likely to be discovered by malicious
users.

Combined, they allow full read access to a victim's file system (including
both directories and files) and scripting access to any domain.

Full details will be released once Opera resolves these issues. In the
meanwhile, users are encouraged not to upgrade to Opera 7 or disable
scripting.


home help back first fref pref prev next nref lref last post