Opera JPEG Processing Integer Overflow Vulnerability
SecurityAlert : 1133 CVE : CVE-2006-3198 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Given : No Credit : VigilantMinds Advisories Published : 28.06.2006
Affected Software :
Opera 8.54 and Earlier
Advisory Text :
Opera JPEG Processing Integer Overflow Vulnerability (VMSA-20060621-01)
Summary:
An integer overflow vulnerability exists in the Opera Web Browser due to
the improper handling of JPEG files.
Impact:
Remote Code Execution
Affected Versions:
Opera 8.54 and Earlier
Details:
If excessively large height and width values are specified in certain
fields of a JPEG file, an integer overflow may cause Opera to allocate
insufficient memory for the image. This will lead to a buffer overflow
when the image is loaded into memory, which can be exploited to execute
arbitrary code.
Recommended Actions:
It is recommended that users upgrade to Opera 9.00, which addresses this
vulnerability. Additionally, users should exercise caution while
accessing the web, and should do so from accounts with limited
privileges.
Timeline:
Reported: 4/25/2006
Fixed: 6/20/2006
Credit:
Chris Ries
References:
Opera Website: http://www.opera.com
VigilantMinds Website: http://www.vigilantminds.com
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.