Opera 7.11/7.20 HREF - Malformed Server Name Heap Corruption

EDB-ID:

23263


Author:

@stake

Type:

dos


Platform:

Multiple

Date:

2003-10-20


source: https://www.securityfocus.com/bid/8853/info

A vulnerability has been discovered in the Opera web browser that could lead to remote code execution. The problem is said to trigger when handling malformed HTML HREF values and may result in a buffer overrun occuring within heap memory. As a result of this issue, an attacker may be capable of executing arbitrary code on a victim user by coaxing them to a malicious web site, or possibly by transmitting a malicious HTML e-mail message to an Opera mail client. 

<a href="file://server%%[many % characters]%%text" ></a>