Phantoms of the Opera fixed

By Matt Loney
06 February 2003 10:50 AM
Tags: greymagic, opera, patch, download
Opera, the Norwegian software company, rushed to release a patch for the latest major release its multi-platform Web browser on Wednesday, following five security advisories that were released on Tuesday, three of them rated critical.

The advisories, from Israeli company GreyMagic Software, were issued just a week after Opera released version 7.0 of its eponymous browser. On Wednesday, those who had downloaded Opera 7.0 were being urged to upgrade to version 7.01, which fixed the bugs. The upgrade is available on Opera's Web site.

The three critical flaws could allow a Web page to collect files from the user's PC. The first, which stems from a problem with Opera's Javascript console, would allow a site to read cookies -- containing information of Web sites visited, and in some cases usernames and passwords -- from a user's PC. A demonstration of this exploit, published by GreyMagic, allowed a user to browse their own file system from a remote Web page.

The second critical vulnerability, called "Phantom of the Opera", also stems from the Javascript console, and again allows a malicious Web page to read any file on the user's file system, said GreyMagic. It also allows a remote Web page to read emails written or received by M2, Opera's mail program.

The third critical exploit uses a flaw in the browser's graphics-handling routines to achieve the same results.

GreyMagic said Opera "lived up to its excellent response record and released version 7.01 only five days after initial notification."

However, the Norwegian firm apparently failed in an earlier attempt to patch the first Javascript bug, which GreyMagic warned of back in November. Opera "apparently failed to understand the core issues and only patched one symptom of the problem," GreyMagic said in its report on the bug.

An Opera spokeswoman said there was "a question of communication -- we did try to address it and we would have liked to have addressed it fully at the time, but we have done it now."

She said Opera has no figures on how many people have downloaded Opera 7.0, but Download.com reports three million downloads of Opera 7.0 since the application was first posted on 28 January, 2003. (Download.com is owned by ZDNet UK parent company CNET Networks.) The spokeswoman said Opera had not heard of any users experiencing problems as a result of the flaws.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured