{"id":410987,"date":"2010-03-10T08:15:06","date_gmt":"2010-03-10T13:15:06","guid":{"rendered":"http:\/\/techie-buzz.com\/?p=20255"},"modified":"2010-04-27T21:48:55","modified_gmt":"2010-04-28T01:48:55","slug":"opera-comes-clean-on-the-malformed-content-length-header-security-issue","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/410987","title":{"rendered":"Opera Comes Clean On the Malformed Content-Length Header Security Issue"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/cache.techie-buzz.com\/images\/posts\/pallab\/opera_10.jpg\" align=\"right\" alt=\"Opera-10.5-Security-Issue\" \/>Last week we reported that a <a href=\"http:\/\/techie-buzz.com\/opera\/vulnerability-opera-windows.html\" title=\"New Highly Critical Vulnerability Discovered in Opera for Windows\">highly critical security vulnerability<\/a> had been uncovered in Opera for Windows. Since then, there have been several conflicting statements from Opera and Secunia regarding the seriousness of the vulnerability.<\/p>\n<p>On one hand, Secunia <a href=\"http:\/\/secunia.com\/advisories\/38820\/\" title=\"View Secunia Advisory\">claimed<\/a> that the vulnerability is serious enough to permit the execution of arbitrary code and can even be used to gain control of the user&#8217;s system. On the other hand, several Opera employees indicated that the vulnerability is <a href=\"http:\/\/twitter.com\/opvard\/status\/10022205189\" title=\"Non-Exploitable Bug\">non-exploitable<\/a>.<\/p>\n<p>A short while ago, both <a href=\"http:\/\/my.opera.com\/securitygroup\/blog\/2010\/03\/09\/the-malformed-content-length-header-security-issue\" title=\"The malformed Content-Length header Security Issue\">Opera Software<\/a> and <a href=\"http:\/\/secunia.com\/blog\/86\/\" title=\"Confusion about Opera vulnerability\">Secunia<\/a> officially issued clarifications regarding this issue. It appears that the confusion arose because the initial proof of concept code shared with Opera was in fact non-exploitable and achieved little more than crashing Opera. Accordingly, Opera Software had issued public statements based on their initial investigations.<\/p>\n<p>On the next day, Secunia contacted Opera and presented a slightly modified scenario. On 64-bit systems, the modified code would still trigger a crash. However, on 32 bit systems it could cause memory corruption and (at least in theory) be exploited to execute arbitrary code. In other words, the original test case was not a security issue but the modified scenario presented by Secunia was.<\/p>\n<p>Opera Software has already prepared a patch and is testing the updated build internally. The patched build should be publically released soon.<\/p>\n<div style=\"font-size:12px\">\n<strong>Share:<\/strong><br \/>\n<a href=\"http:\/\/techie-buzz.com\/opera\/opera-security-content-length-header.html#commentrespond\" rel=\"bookmark\" >Comment on This Post<\/a> |<br \/>\n<a href=\"http:\/\/twitter.com\/home?source=techiebuzz&#038;status=Opera%20Comes%20Clean%20On%20the%20Malformed%20Content-Length%20Header%20Security%20Issue%20Opera+Malformed+Content-Length+Header+Security+Issue+%7C+Clarifications+from+Opera+and+Secunia%20via%20@techiebuzzer\" rel=\"bookmark\" >Tweet This<\/a> |<br \/>\n<a href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/techie-buzz.com\/opera\/opera-security-content-length-header.html\" rel=\"bookmark\" >Share on Facebook<\/a> |<br \/>\n<a href=\"http:\/\/del.icio.us\/post?url=http:\/\/techie-buzz.com\/opera\/opera-security-content-length-header.html&#038;title=Opera%20Comes%20Clean%20On%20the%20Malformed%20Content-Length%20Header%20Security%20Issue\" rel=\"bookmark\" >Save to Delicious<\/a> |<br \/>\n<a href=\"http:\/\/www.stumbleupon.com\/submit?url=http:\/\/techie-buzz.com\/opera\/opera-security-content-length-header.html\" rel=\"bookmark\" >Stumble This<\/a> |<br \/>\n<a href=\"http:\/\/digg.com\/submit?phase=2&#038;url=http:\/\/techie-buzz.com\/opera\/opera-security-content-length-header.html&#038;title=Opera%20Comes%20Clean%20On%20the%20Malformed%20Content-Length%20Header%20Security%20Issue\" rel=\"bookmark\" >Digg This<\/a> |<br \/>\n<a href=\"http:\/\/www.reddit.com\/submit?url=http:\/\/techie-buzz.com\/opera\/opera-security-content-length-header.html&#038;title=Opera%20Comes%20Clean%20On%20the%20Malformed%20Content-Length%20Header%20Security%20Issue\" rel=\"bookmark\" >Reddit This<\/a>\n<\/div>\n<div><strong style=\"font-size:11px;\">TAGS:<\/strong> <span style=\"text-transform:uppercase;font-size:11px;\"><a href=\"http:\/\/techie-buzz.com\/tag\/browser\" rel=\"tag\">browser<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/internet-browsers\" rel=\"tag\">Internet Browsers<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/online-security\" rel=\"tag\">Online Security<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/opera\" rel=\"tag\">Opera<\/a>, <a href=\"http:\/\/techie-buzz.com\/tag\/security\" rel=\"tag\">Security<\/a><\/span><br \/>\n<\/small><\/div>\n<div style=\"background:#E1E1E1; border: dotted 1px; padding:5px; margin-top:5px;font-size:11px\">\n<a href=\"http:\/\/techie-buzz.com\/opera\/opera-security-content-length-header.html\" title=\"Opera Comes Clean On the Malformed Content-Length Header Security Issue\">Opera Comes Clean On the Malformed Content-Length Header Security Issue<\/a> originally appeared on <a href=\"http:\/\/techie-buzz.com\" title=\"Techie Buzz\">Techie Buzz<\/a> written by Pallab De on Wednesday 10th March 2010 08:15:06 AM. Please read the <a href=\"http:\/\/techie-buzz.com\/terms-of-use\">Terms of Use<\/a> for fair usage guidance. <\/div>\n<p><\/p>\n<h2>Don&#8217;t miss these Related Posts:<\/h2>\n<ul>\n<li><a href=\"http:\/\/techie-buzz.com\/opera\/vulnerability-opera-windows.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >New Highly Critical Vulnerability Discovered in Opera for Windows<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/opera\/opera-10-01-fix-security-vulnerabilities.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Opera 10.01 Released &#8211; Fixes Multiple Security Vulnerabilities<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/tech-news\/serious-security-hole-opera-browser.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Serious Security Hole in Opera Browser<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/tech-news\/internet-explorer-vulnerability-firefox-opera-downloads.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >Internet Explorer Vulnerability Causes Downloads of Firefox and Opera to Surge in Germany<\/a><\/li>\n<li><a href=\"http:\/\/techie-buzz.com\/opera\/view-opera-cache-content-with-opera-cache-viewer.html??rel=rss_related&#038;utm_source=self&#038;utm_medium=web&#038;utm_campaign=rss_related\" rel=\"bookmark\" >View Opera Cache Content With Opera Cache Viewer<\/a><\/li>\n<\/ul>\n<h2>Join Techie Buzz on Your Favorite Social Networking Sites<\/h2>\n<ul>\n<li><a href=\"http:\/\/go.techie-buzz.com\/facebookfanrss\" title=\"Become a Techie Buzz fan on Facebook\">Become a Techie Buzz fan on Facebook<\/a><\/li>\n<li><a href=\"http:\/\/go.techie-buzz.com\/twitterrss\" title=\"Follow Techie Buzz on Twitter\">Follow Techie Buzz on Twitter<\/a><\/li>\n<\/ul>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/KLzCfcb7yTf6ijdFD3tbATc544I\/0\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/KLzCfcb7yTf6ijdFD3tbATc544I\/0\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/KLzCfcb7yTf6ijdFD3tbATc544I\/1\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/KLzCfcb7yTf6ijdFD3tbATc544I\/1\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/techiebuzz\/~4\/lZpnQ8e98Ro\" height=\"1\" width=\"1\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week we reported that a highly critical security vulnerability had been uncovered in Opera for Windows. Since then, there have been several conflicting statements from Opera and Secunia regarding the seriousness of the vulnerability. On one hand, Secunia claimed that the vulnerability is serious enough to permit the execution of arbitrary code and can [&hellip;]<\/p>\n","protected":false},"author":1716,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-410987","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/410987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/1716"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=410987"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/410987\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=410987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=410987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=410987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}