Opera Gets Incremental Upgrade
- 0
- Add a Comment
Always quick to plug leaks, the Opera team has once again taken time off from work on the version 10 beta and pumped out a bug fix for version 9.6.
Opera plugs security holes; adds ALSR , DEP support
Opera Software has shipped a high-priority security patch for its flagship Web browser to plug at least three vulnerabilities that expose Windows users to code execution and cross-domain scripting attacks.
The Opera 9.64 upgrade also adds support for DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization), two anti-exploitation mechanisms that helps to limit the damage from malware attacks on the Windows platform.
Opera has only released details on one of the three security vulnerabilities, which was discovered and reported by Google’s Tavis Ormandy.
Specially crafted JPEG images can cause Opera to corrupt memory and crash. Successful exploitation can lead to execution of arbitrary code.Opera said the update also fixes an issue where plug-ins could be used to allow cross domain scripting and a third “moderately severe” issue that remains a mystery.
Since Ryan Naraine, from ZDNet stays fully up to date on these developments, an update on what the third problem is will be forthcoming.
Try or upgrade now! or learn more.
§
•


