Description: Opera has been found vulnerable to a buffer overflow in the handling of filenames when showing the "Download Dialog" box.
The problem is that very long filenames are handled incorrectly. This allows a malicious website to create a filename that causes a buffer overflow which can be exploited to execute arbitrary code.
Exploits are in the wild for Windows.
Exploitation does not require user interaction as websites can spawn the "Download Dialog" automatically.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Solution: Upgrade to version 7.0.3.
Provided and/or discovered by: nesumin
Changelog: 2003-03-12: Opera has promised an update within 24 hours according to digi.no.
2003-03-13: Opera has released version 7.0.3.
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
49 Related Secunia Security Advisories, displaying 10
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.