'Highly critical' flaw found in Opera browser

Security researchers are sounding the alarm for an unpatched, remote code execution flaw in the Opera Web browser.

The vulnerability, rated “highly critical” by Secunia, can be exploited by malicious people to take complete control a user’s system.

From Secunia’s advisory:

The vulnerability is caused due to an error when processing HTTP responses having a malformed “Content-Length” header. This can be exploited to cause a heap-based buffer overflow via an overly large 64-bit “Content-Length” value, having the higher 32-bit part negative.

The vulnerability is confirmed in version 10.50 for Windows. Other versions may also be affected.

In the absence of a patch, Opera users are urged to avoid browsing to untrusted Web sites or switch to an alternative browser.

http://blogs.zdnet.com/security/?p=5619&tag=col1;post-5619

The issue is highly overhyped as far as i could see…

Well its about time “they” found a flaw with Opera ;D

As long as you browse carefully, that vulnerability wont be a bother^^

-AnimeLover^^

yeah…year after year…still waiting for that hacker over there to take advantage of that flaw allowing him to gain access and control my computer ;D where is he ???

I haven’t seen any reports of exploits in the wild yet.