copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ASB-2011.0071.2 - UPDATE [Win][UNIX/Linux] Opera: Multiple vulnerabilities

Date: 09 September 2011
References: ESB-2011.0979  ESB-2011.1033  ESB-2011.1032  ESB-2011.1041  ESB-2011.1052  ASB-2011.0092  ESB-2011.1055  ASB-2011.0120  ESB-2011.1273  ESB-2012.0044  
ESB-2012.0069  ESB-2012.0081  ESB-2012.0218  ESB-2012.0343  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                              ASB-2011.0071.2
         A number of vulnerabilities have been identified in Opera
                             9 September 2011

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Opera
Operating System:     Windows
                      UNIX variants (UNIX, Linux, OSX)
Impact/Access:        Provide Misleading Information -- Remote with User Interaction
                      Reduced Security               -- Unknown/Unspecified         
Resolution:           Patch/Upgrade
CVE Names:            CVE-2011-3389 CVE-2011-3388 
Member content until: Saturday, October  1 2011

Revision History:     September 9 2011: Added CVE's
                      September 1 2011: Initial Release

OVERVIEW

        A number of vulnerabilities have been identified in Opera prior to
        version 11.51.


IMPACT

        The vendor has provided the following details regarding these
        vulnerabilities:
        
        "Insecure sites should be shown in the address field as insecure 
        (displayed as "Web" in the address field). When certain content is 
        loaded and manipulated in a specific sequence, it can cause Opera to 
        display the security information from the loaded resources in the 
        address field and page information dialog. This allows a malicious 
        page to display the security information from a secure or trusted 
        third party, instead of its own security information." [1]
        
        "Fixed a low severity issue, as reported by Thai Duong and Juliano 
        Rizzo; details will be disclosed at a later date" [2]


MITIGATION

        The vendor recommends upgrading to the latest version of Opera
        to correct these issues. [2]


REFERENCES

        [1] Unsecured web content may appear to be secure or trusted through
            Extended Validation
            http://www.opera.com/support/kb/view/1000/

        [2] Opera 11.51 for Windows changelog
            http://www.opera.com/docs/changelogs/windows/1151/

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBTml/B+4yVqjM2NGpAQJRCQ/+NnogNes//CW/k6eHFjUjK5SYrM5FjZMW
f9pQ6qPdHp0RbofixwKO1kvE8zFUv/QGdlPGfojk9Kp3baTjv9fk+FCOfsQ0hsfw
VsvBnqfoHhxth5eVTOreuHHOP9nGlhPcj3GChoCafo2rtg8cVmqjIou5mzbdaIbN
9ujQjWMx9kOLsMttSWZqqj0fX6K04tMMd1oiheeqvJF30mPHL83Me6yBZVbqqFUo
oMVX0w7EozrpbSGKEiqkTtMemFWIuJ2dwDIs+/ymQkRmKk5ppcHC5tQdxMUjDuSP
lSGHVq+EbyJK78eal3DgfCX6ZrUxGdw5MuU1XWZmWQ8cSZGH/KXyPeNLe9SFzDQi
PvnLITF9Eduz4R/a5SSBK/vgjxuyHTVA6F9aY8ogMLOdwuUJgPbkmUxQ/seOydQs
CCd4Fp1sJGGBJ/LJdwFxVEiJrXx9/5DdVxoVmot0zNICmRbfl3sOLDQKrQsUJbPC
rZevxtaT5My8NH6SF7TquepJSDMrQ9bqyjyim7MRqkfK5oh9wcynC1bZLO8knqlI
AoAiILeXsF/GGLwOzloiDE+12wJx24VTyXX6ajWV99snYj9O+DIslUVnQ+Nh7zrp
FjzzFPZ3Ss1pjoKgbJdygpZ51XVU9VjzLzxlJ5ruEnZ4H7jEcqhhzKvvNAUt3zb4
b0yhdDAGSNI=
=YqF8
-----END PGP SIGNATURE-----