Opera: Multiple vulnerabilities — GLSA 201406-14

Multiple vulnerabilities have been found in Opera, the worst of which may allow remote execution of arbitrary code.

Affected Packages

www-client/opera on all architectures
Affected versions < 12.13_p1734
Unaffected versions >= 12.13_p1734

Background

Opera is a fast web browser that is available free of charge.

Description

Multiple vulnerabilities have been discovered in Opera. Please review the CVE identifiers referenced below for details.

Impact

A remote attacker could entice a user to open a specially crafted web page using Opera, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Furthermore, a remote attacker may be able to obtain sensitive information, conduct Cross-Site Scripting (XSS) attacks, or bypass security restrictions.

A local attacker may be able to obtain sensitive information.

Workaround

There is no known workaround at this time.

Resolution

All Opera users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=www-client/opera-12.13_p1734"
 

References

Release Date
June 15, 2014

Latest Revision
June 15, 2014: 1

Severity
normal

Exploitable
local, remote

Bugzilla entries