Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 508718 - www-client/opera : OpenSSL TLS/DTLS Heartbeat Two Information Disclosure Vulnerabilities
Summary: www-client/opera : OpenSSL TLS/DTLS Heartbeat Two Information Disclosure Vuln...
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://secunia.com/advisories/58125/
Whiteboard: B3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-04-25 20:02 UTC by Agostino Sarubbo
Modified: 2014-04-25 20:18 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-04-25 20:02:34 UTC
From ${URL} :

Description

Opera has acknowledged two vulnerabilities in Opera, which can be exploited 
by malicious people to disclose potentially sensitive information.

The vulnerabilities are caused due to a bundled vulnerable version of 
OpenSSL.

For more information:
SA57347

The vulnerabilities are reported in versions prior to 12.17.


Solution:
Update to version 12.17.

Original Advisory:
http://www.opera.com/docs/changelogs/windows/1217/
http://blogs.opera.com/desktop/2014/04/opera-12-17/
http://blogs.opera.com/security/2014/04/heartbleed-heartaches/


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2014-04-25 20:18:07 UTC
That's a bug in the Microsoft Windows downloader/installer app for Opera.

http://blogs.opera.com/desktop/2014/04/opera-12-17/

"Mac and Linux are not affected, and will not receive a 12.17 update."