Three high-severity vulnerabilities have also been eliminated

Aug 2, 2012 11:31 GMT  ·  By

Besides delivering stability improvements, the freshly launched Opera 12.01 also plugs a few security holes, among which a critical one that consisted in allowing arbitrary code execution by certain URL constructs.

Some page address constructs would cause Opera to allocate the wrong amount of memory for storing the address. Attempting to store that address would cause unrelated memory to be overwritten with attacker-controlled data. A crash is likely to ensue, which could trigger the execution of the malicious data as code.

This problem has also been addressed in version 11.64 of the browser.

A set of three high-severity risks have also been eliminated. Two of them could have been exploited to carry out cross-site scripting attacks because of some characters in HTML being incorrectly ignored and element HTML content can be incorrectly returned without escaping, thus getting by the sanitizer.

The third security fix refers to Opera generating a very small download window, increasing the chances for the user to miss it and thus download malware on the system.

Download Opera for Windows
Download Opera for Mac
Download Opera for Linux