Attack code circulated on the Internet.
Opera Software has led him to be released Opera 10.50 at the same time as Microsoft rolls out the screen for the browser options in Windows. It is the Norwegian company has managed, but now it seems that a serious vulnerability could destroy some of the joy.
The day after the site was launched in 10.50, went Marcin Ressel with information about a serious vulnerability in the browser. The information also includes sample code for how the vulnerability, which allows execution of arbitrary code, can be exploited.
In addition to the latest version, found the vulnerability in any case, also in Opera 10.10 for Windows.
According to security company Secunia the vulnerability is due to an error in the processing of HTTP response messages that have a deformed "Content-Length" header. This can be exploited to create a head-based buffer overflow via an overly large 64-bit "Content-Length" value where the highest 32-bit part is negative.
Successful exploitation of the vulnerability allows arbitrary code.
Until Opera Software has come with a security update, Opera users should refrain from visiting unknown sites.
End Of Post