Opera heeft naar aanleiding van enkele beveiligingsbugs in zijn Opera-webbrowser in de vorm van 7.54u1 een nieuwe versie van de internetsurfer uitgebracht. Deze versie is te downloaden in twee verschillende uitoeringen: de eerste download bestaat uit Opera 7.54u1 zonder Java, terwijl de tweede download een paar megabyte zwaarder is en met Java geleverd wordt. Welke security bugs gedricht zijn is hieronder te lezen. Volgens DataGhost zijn in versie 7.54u1 ook de bugfixes doorgevoerd die in de preview versie te vinden waren:
Opera security advisoryOpera's response
- Named frames or windows can be hi-jacked by malicious frames or windows.
- Periods in the file name and non-breaking spaces in the Content-Type header can make the save/open dialog misleading. A user may be convinced that an executable file is something else, for example a PDF document.
- Applets have access to sun.* packages
- Liveconnect: com.opera.EcmascriptObject constructor is accessible to Java
- Liveconnect reveals the path to the user's home directory. This can make other vulnerabilities easier to exploit.
- Tightened origin check for frames. A side effect of this is that documents not passing the origin check will open in a new page.
- Fixed issue reported by Marc Schönefeld: intrusive JavaScript or Java applet could exploit Sun Java vulnerability to retrieve logged-in user's username and install directory.
- Fixed LiveConnect class access security issue reported by Jouko Pynnonen.
- Fixed Secunia issue SA12981, reported by Andreas Sandblad: periods in the file name and non-breaking spaces in content-type header type could obscure the file type.
- Fixed Secunia issue SA13253: "hi-jacking" a named browser window.
- Improved support for the "must-revalidate" cache directive.