Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VULNERABILITIES - December 12, 2005

Dec 12, 2005 5:42AM PST

TITLE:
Opera Bookmark Large Title Denial of Service Weakness

SECUNIA ADVISORY ID:
SA17963

VERIFY ADVISORY:
http://secunia.com/advisories/17963/

CRITICAL:
Not critical

IMPACT:
DoS

WHERE:
From remote

SOFTWARE:
Opera 8.x
http://secunia.com/product/4932/

DESCRIPTION:
A weakness has been reported in Opera, which can be exploited by
malicious people to cause a DoS (Denial of Service).

The weakness is caused due to an error in the handling of large page
titles. This can be exploited by tricking a user into bookmarking a
page with an overly long title.

Successful exploitation causes the browser to crash when the affected
browser is started up again after an attack, but requires that the
Input Method Editor (IME) is installed. Users may have to remove the
"autosave.win" file in order to be able to use the affected browser.

SOLUTION:
Update to version 8.51.
http://www.opera.com/download/

PROVIDED AND/OR DISCOVERED BY:
The vendor credits Tatsuya Matsumoto and jp-CERT.

ORIGINAL ADVISORY:
Opera:
http://www.opera.com/support/search/supsearch.dml?index=821

Discussion is locked