Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 137634 - www-client/opera JPEG Processing Integer Overflow Vulnerability
Summary: www-client/opera JPEG Processing Integer Overflow Vulnerability
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.opera.com/support/search/s...
Whiteboard: B2 [invalid] DerCorny
Keywords:
Depends on: 137357
Blocks:
  Show dependency tree
 
Reported: 2006-06-22 11:35 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2008-03-06 09:32 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-22 11:35:30 UTC
Summary:
 An integer overflow vulnerability exists in the Opera Web Browser due to
 the improper handling of JPEG files.
 
 Impact:
 Remote Code Execution
 
 Affected Versions:
 Opera 8.54 and Earlier
 
 Details:
 If excessively large height and width values are specified in certain
 fields of a JPEG file, an integer overflow may cause Opera to allocate
 insufficient memory for the image. This will lead to a buffer overflow
 when the image is loaded into memory, which can be exploited to execute
 arbitrary code.
 
 Recommended Actions:
 It is recommended that users upgrade to Opera 9.00, which addresses this
 vulnerability. Additionally, users should exercise caution while
 accessing the web, and should do so from accounts with limited
 privileges.
 
 Timeline:
 Reported: 4/25/2006
 Fixed: 6/20/2006
 
 Credit:
 Chris Ries
 
 References:
 Opera Website: http://www.opera.com
 VigilantMinds Website: http://www.vigilantminds.com
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2006-06-22 11:55:20 UTC
axxo please have a look and provide new ebuilds if possible
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-30 05:22:35 UTC
I'd do the update, if no one complains. axxo is busy accoring to his devaway entry.
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-30 08:08:38 UTC
Carlo please do:-)
Comment 4 Carsten Lohrke (RETIRED) gentoo-dev 2006-06-30 12:00:08 UTC
In cvs. Arch herds, here's something to snack for you. :)
Comment 5 Thomas Matthijs (RETIRED) gentoo-dev 2006-06-30 18:22:09 UTC
It was bumped see dependant bug, please undo your changes
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-01 00:08:00 UTC
Thomas is this ready for stable marking and in that case which version?

Next time please update the security bug when you do a bump, I also missed the dependant bug.

Back to ebuild until this gets sorted.
Comment 7 Thomas Matthijs (RETIRED) gentoo-dev 2006-07-01 03:02:29 UTC
9.00 should be ready
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-01 04:38:52 UTC
Arches please test and mark stable.
Comment 9 Carsten Lohrke (RETIRED) gentoo-dev 2006-07-01 05:06:17 UTC
(In reply to comment #5)
> It was bumped see dependant bug, please undo your changes
> 

Sorry Thomas, that I didn't notice. Ebuild is restored.
Comment 10 Lars Weiler (RETIRED) gentoo-dev 2006-07-01 05:16:18 UTC
Stable on ppc.
Comment 11 Jesus de Santos Garcia 2006-07-01 09:21:21 UTC
x86 is fine, working perfectly.
Comment 12 Thomas Cort (RETIRED) gentoo-dev 2006-07-02 21:02:41 UTC
amd64 stable.
Comment 13 Gustavo Zacarias (RETIRED) gentoo-dev 2006-07-03 14:43:42 UTC
sparc stable.
Comment 14 Christian Faulhammer (RETIRED) gentoo-dev 2006-07-04 00:21:53 UTC
1) emerges fine
2) runs fine on KDE and Gnome (surfed a bit more on the latter)

Portage 2.1-r1 (default-linux/x86/no-nptl, gcc-3.4.6, glibc-2.3.6-r4, 2.6.16-gentoo-r9 i686)
=================================================================
System uname: 2.6.16-gentoo-r9 i686 AMD Athlon(tm) XP 2500+
Gentoo Base System version 1.6.15
dev-lang/python:     2.4.3-r1
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     [Not Present]
dev-util/confcache:  [Not Present]
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.59-r7
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.13-r2
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.11-r2
ACCEPT_KEYWORDS="x86"
AUTOCLEAN="yes"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O0"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/X11/xkb"
CONFIG_PROTECT_MASK="/etc/env.d /etc/gconf /etc/revdep-rebuild /etc/splash /etc/terminfo"
CXXFLAGS="-O0"
DISTDIR="/usr/portage/distfiles"
FEATURES="autoconfig ccache collision-protect distlocks metadata-transfer parallel-fetch sandbox sfperms strict test"
GENTOO_MIRRORS="ftp://sunsite.informatik.rwth-aachen.de/pub/Linux/gentoo/"
LANG="de_DE@euro"
LC_ALL="de_DE@euro"
LINGUAS="de"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude='/distfiles' --exclude='/local' --exclude='/packages'"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.informatik.rwth-aachen.de/gentoo-portage"
USE="x86 3dnow 3dnowext X Xaw3d a52 alsa arts artworkextra asf audiofile avi bash-completion berkdb bidi bitmap-fonts bootsplash bzip2 cairo cdda cddb cdparanoia cdr cli cracklib crypt css cups curl custom-cflags dbus dga directfb divx4linux dlloader dri dts dvd dvdr dvdread dvi eds emacs emboss encode esd evo exif expat fam fat fbcon fdftk ffmpeg firefox foomaticdb fortran ftp gb gcj gdbm gif gnome gpm gstreamer gtk gtk2 gtkhtml hal howl icq idn imagemagick imap imlib ipv6 isdnlog java javascript jikes jpeg jpeg2k kde ldap leim libg++ libwww lm_sensors mad maildir matroska mbox mikmod mime mmx mmxext mng mono motif mp3 mpeg mpeg2 mule nautilus ncurses nforce2 nls nocardbus nowebdav nsplugin nvidia ogg opengl pam pcre pdf pdflib perl plotutils pmu png ppds pppd preview-latex print python qt qt3 qt4 quicktime readline reflection reiserfs samba sdk session slang spell spl sse ssl svg svga t1lib tcltk tcpd theora thunderbird tiff truetype truetype-fonts type1-fonts usb vcd videos vorbis win32codecs wmf wxwindows xine xml xmms xorg xosd xv xvid zlib elibc_glibc input_devices_mouse input_devices_keyboard kernel_linux linguas_de userland_GNU video_cards_radeon video_cards_vesa video_cards_fbdev"
Unset:  CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LDFLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 15 Joshua Jackson (RETIRED) gentoo-dev 2006-07-05 09:52:17 UTC
x86 done now, sorry about the delay ^.^;;
Comment 16 Stefan Cornelius (RETIRED) gentoo-dev 2006-07-05 09:54:38 UTC
Not closed yet, GLSA still needs to be send
Comment 17 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-09 10:21:34 UTC
Vendor says:

Not affected: Opera for Linux, FreeBSD and Solaris.

At least we got Opera 9 stabled:-)

Comment 18 Peter Volkov (RETIRED) gentoo-dev 2008-03-06 09:32:26 UTC
Does not affect current (2008.0) release. Removing release.