• Home
  • Advertise
  • Contact Us
  • Free eBooks
  • Infographics
  • About Us


  • Technology
    • Programming
      • Java
      • PHP
      • HTML
      • CSS
      • Javascript
      • XML
      • AJAX
      • JQuery
      • Perl
      • IDE
    • CMS
      • Opencart
      • WordPress
      • Prestashop
      • Magento
    • Database
  • Security
    • Cyber Laws
    • Digital Signature
    • Passwords
    • Reverse Engineering
    • Steganography
    • Forensics
    • Networking
  • E-Commerce
  • Digital Media
    • SEO
    • Social Media
      • Facebook
  • Gadgets
    • Laptops
    • Tablets
    • Just CellPhones
    • Social CellPhones
  • OS
    • Linux
    • Mac
    • Windows
    • iOS
    • Android
  • Courses
    • Development in Android
  • General

Breaking

The supercomputer "Tianhe-2" Takes No. 1 Ranking on 41st TOP500 List

Export tweets in different formats

OWASP - Top 10 Vulnerabilities

New Windows-backdoor deletes MBR

The world's first CPU of 5GHz

Critical vulnerability in 60 + models of CCTV and IP-cameras

Hack a Samsung TV with SmartTV function

The man who "almost broke the Internet"

The search continues for the sixth member of LulzSec

Statistics on the botnet Carna


Opera 12.11 vulnerability when opening a GIF-file

0 Comment
 04 Dec 2012   Posted by synt4x

1 Star2 Stars3 Stars4 Stars5 Stars
Loading ... Loading ...


flattr this!

In the browser Opera 12.11 there is vulnerable Write AV , which is shown when you open a GIF-file which crashes the browser.

Because of incorrect exception handling in Opera when opening a specially crafted GIF-file there is heap corruption. Theoretically, this vulnerability in the browser can be used to create malicious exploits, so to fix this using this browser may not be safe.

It should be noted that this is not the first problem with security in Opera recently. In early October 2012 vulnerability was discovered in Opera 12, which allows you to use images and specific headers to redirect visitors to another site. Many sites have been a victim of this vulnerability.

If the code page is opened, an attacker could place a tag like this:
< img src="hxxp://evil.com/evil.png" alt="" / >
(Where evil.com – controlled by the server)

and pay when prompted http://evil.com/evil.png following headline:

Refresh: 0; url = data: application / internet-shortcut, [INTERNETSHORTCUT]% 0D% 0AURL = http://evil.com/
the browser Opera 12 will automatically jump to that address.

Opera Company representatives said they did not consider this vulnerability, and blame the owners of websites that “do not hold control input from untrusted users.” Despite this, browser developers have decided to meet webmasters – and fixed the “You” in the version of Opera 12.10.

Spread The Word:

  • Facebook
  • Twitter
  • Pinterest
  • StumbleUpon
  • Google +1
  • Digg
  • Reddit
  • Email
  • LinkedIn
  • Tumblr
    Share This


Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • Find Us On Facebook

  • Airtel Hello Tunes

  • Ads.

  • Ads.

  • Shrugs Online


  • More...

    • Advertise
    • Crawl Fashion | Fashion Directory
    • Information Technology Act 2000 Compliance [Sec 43A and Sec 72A]
    • Java Tutorial
    • Netbeans Tutorial
    • Photography Blogs
    • Street Shopping
    • Virus Protection And Internet Security
  • Recent Posts

    • OWASP - Top 10 Vulnerabilities
    • New Windows-backdoor deletes MBR
    • Critical vulnerability in 60 + models of CCTV and IP-cameras
    • Hack a Samsung TV with SmartTV function
    • The man who "almost broke the Internet"
    • The search continues for the sixth member of LulzSec
  • Enter your email address to subscribe to "Bytes" Mag & receive THE latest updates on Tech!


Copyright © LetsByteCode Inc.
DMCA.com
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.