HTTP: Opera File URL Overflow

This signature detects attempts to exploit a known vulnerability in Opera Software (version 9.62 and prior). An attacker can create a malicious Web site containing dangerous URL links, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Opera Web Browser is prone to a heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input before copying it to an insufficiently sized buffer. Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions. Opera Web Browser 9.62 is vulnerable; other versions may also be affected.

Affected Products

Opera_software opera_web_browser

References

CVE: CVE-2008-5683

Short Name
HTTP:STC:OPERA:FILE-URL-OF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2008-5178 CVE-2008-5679 CVE-2008-5680 CVE-2008-5681 CVE-2008-5682 CVE-2008-5683 File Opera Overflow URL
Release Date
08/18/2009
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3360
False Positive
Unknown
Vendors

Opera_software

Gentoo

CVSS Score

9.3

7.8

4.3

Found a potential security threat?