Opera Web Browser WebP graphics information leakage Vulnerability
Release date:
Updated on:
Affected Systems:
Opera Software Opera Web Browser <12.10
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57120
CVE (CAN) ID: CVE-2012-6466
Opera is a browser from Norway that features fast speed, saving system resources, strong customization ability, high security, and small size. It is one of the most popular browsers.
In versions earlier than Opera Web Browser 12.10, malformed data length fields in WebP images were not correctly processed. by constructing a specially crafted image file, remote attackers can exploit this vulnerability to obtain sensitive information in memory.
<* Source: vendor
Google Security Team
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-6466
Http://www.opera.com/docs/changelogs/unified/1210/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Opera Software
--------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.opera.com/download/