Alert Number: 100808-01
Alert Date: 10/08/08
Alert Title: Opera update addresses three security issues
Update-to: None.
OS/Platform/Application:
Opera web browser all versions older than 9.60
Category: ALERT
Severity: HIGH
Attention: Opera Users, System Administrators, Desktop Support Personnel.
Summary: Opera Software ASA has released version 9.60 of its popular web browser software. In addition to numerous performance and accessibility improvements the new version of software includes fixes for three security-related issues. One fix addresses a vulnerability that could result in application/system crash or takeover of a vulnerable computer if a user was tricked into visiting a maliciously-crafted website address. Another fix addresses a problem with java applet caching that could allow for the disclosure of private or sensitive information. The third update improves handling of verified websites.
Recommended Actions: Opera users, support personnel and system administrators are encouraged to read the security bulletins and apply the update at their earliest convenience.
Readers are encouraged to share this alert with family, friends, and associates.
ITS Actions: N/A
Resources:
Opera Security Advisory (details website redirect vulnerability):
http://www.opera.com/support/search/view/901/
Opera Security Advisory (details java applet handling vulnerability):
http://www.opera.com/support/search/view/902/
Opera RootStore Blog Entry (details website verification changes in Opera 9.60):
http://my.opera.com/rootstore/blog/2008/09/12/verisign-and-comodo-formally-ev-enabled
Opera (Windows) release notes:
http://www.opera.com/docs/changelogs/windows/960/
Opera Download Page:
http://www.opera.com/download/