Opera HREF恶意服务器名堆损坏漏洞

漏洞信息详情

Opera HREF恶意服务器名堆损坏漏洞

漏洞简介

Opera 7.11和7.20版本存在基于堆的缓冲区溢出漏洞。远程攻击者借助服务器名里具有大量转义字符的HREF执行任意代码。

漏洞公告

Gentoo has released an advisory that includes updates to address this issue. The following commands may be used to apply these updates:
emerge –sync
emerge ‘>=net-www/opera-7.22’
emerge clean
The vendor has released Opera 7.21 to address this issue. Users are urged to upgrade as soon as possible.
Opera Software Opera Web Browser 7.11

Opera Software Opera Web Browser 7.20

参考网址

来源: XF
名称: opera-escape-heap-overflow(13458)
链接:http://xforce.iss.net/xforce/xfdb/13458

来源: BID
名称: 8853
链接:http://www.securityfocus.com/bid/8853

来源: ATSTAKE
名称: A102003-1
链接:http://www.atstake.com/research/advisories/2003/a102003-1.txt

来源: VULNWATCH
名称: 20031020 Opera HREF escaped server name overflow
链接:http://archives.neohapsis.com/archives/vulnwatch/2003-q4/0016.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享