Search Opera's knowledge base:


Or, you may browse the articles.

Advisory: A JPEG image with a malformed header can crash Opera

Platform: All desktop versions

Summary

A JPEG image with a malformed header can crash Opera, and cause arbitrary code to be run.

Severity: Moderate

Problem description

A specially crafted DHT marker in the JPEG file header can cause a heap overflow.

The malformed image alone will only cause a crash. To exploit the flaw, the computer's memory must first be filled up with code of the attacker's choice. This is not trivial to do reliably, so attempted attacks will often cause crashes without succeeding with the exploit.

Opera's response

Opera Software has released Opera version 9.10, where this flaw has been corrected.

Credits

Thanks to iDefense Labs for notifying Opera Software about this vulnerability.

Last edited: 2007-01-05; Category: Security advisories; Keywords: advisory,; Index: 852