nsane.forums: Opera users baffled by vulnerability warnings - nsane.forums

Jump to content

Welcome to nsane.forums

Welcome to nsane.forums, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information. Take advantage of it immediately, Register Now or Sign In.

  • Start new topics and reply to others
  • Subscribe to topics and forums to get automatic updates
  • Access to special member only forums
  • Get your own profile and make new friends
  • Customize your experience here
  • ... and much more!
Guest Message © 2010 DevFuse

Software News - Posting Guidelines

Please Note: This forum should be used to post news relating to software. Please use the "Software Updates" sub-forum to post information about new application releases.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Opera users baffled by vulnerability warnings Rate Topic: -----

#1 User is offline   News Bot 

  • I'm a Bot
  • Group: ViP
  • Posts: 522
  • Joined: 24-January 09

  • Cape Verda

Posted 09 March 2010 - 11:32 AM

Posted Image

Security vendors sending out misleading information, claims Secunia

Confusion about the severity of a newly reported Opera flaw could be harming efforts to mitigate the threat, according to experts.

Secunia claimed in a blog post that security companies are sending out mixed messages about the vulnerability, including inaccurate information on its effects and causes.

The security firm said that it had spent time properly analysing the flaw's impact, and had concluded that it is far less severe than users may have been led to believe.

"Before issuing a Secunia advisory, a security specialist was tasked with thoroughly analysing the vulnerability report, the cause of the crash and its potential impact," wrote Carsten Eiram, chief security specialist at Secunia.

Eiram explained that the vulnerability is not caused by an integer overflow error, as other security companies have reported.

"Instead, in certain cases when a 64-bit 'Content-Length' value is interpreted as negative, the higher 32-bit value is ignored and the lower 32-bit value is used to copy data," he said.

"It is therefore possible to manipulate the size value in a manner to successfully corrupt memory and occasionally cause conditions where it is possible to gain control of the execution flow."

Eiram went on to assert that at least one of Secunia's competitors misled users.

"At least one other site did, as usual, abuse the opportunity to hype the vulnerability and refer to it as a zero-day, which is misleading as no working exploit has been published nor is the vulnerability being actively exploited," he wrote.

"Instead, it was an uncoordinated, commonly termed 'irresponsible', disclosure as the vulnerability report was published without the reporter first informing the vendor."

Secunia has worked with Opera in analysing the issue, and the browser maker has promised to issue a security advisory and a fix as soon as possible.


Posted Image View: Original Article
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic



1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users