Bug 8162 - [Update Request]Update opera to latest stable version to fix several security problems
: [Update Request]Update opera to latest stable version to fix several security...
Status: RESOLVED FIXED
Product: Mageia
Classification: Unclassified
Component: Security
: 2
: All Linux
: Normal Severity: normal
: ---
Assigned To: QA Team
:
: http://www.opera.com/docs/changelogs/...
: MGA1TOO MGA2-64-OK MGA2-32-OK MGA1-64...
: validated_update
:
:
  Show dependency treegraph
 
Reported: 2012-11-20 10:41 CET by Funda Wang
Modified: 2012-11-26 15:16 CET (History)
3 users (show)

See Also:
Source RPM: opera-12.11-1.mga2
CVE:
Status comment:


Attachments

Description Funda Wang 2012-11-20 10:41:58 CET
The opera package prior to 12.11 contains several security problems:

* HTTP response heap buffer overflow can allow execution of arbitrary code.
  http://www.opera.com/support/kb/view/1036/

* Error pages can be used to guess local file paths.
  http://www.opera.com/support/kb/view/1037/

Opera has been updated to 12.11 to fix above problems.
Comment 1 Dave Hodgins 2012-11-20 20:02:37 CET
Testing complete on Mageia 1 and 2, i586 and x86-64.

Could someone from the sysadmin team push the srpm
opera-12.11-1.mga2.nonfree.src.rpm
from Mageia 2 Nonfree Updates Testing to Nonfree Updates and the srpm
opera-12.11-1.mga1.nonfree.src.rpm
from Mageia 1 Nonfree Updates Testing to Nonfree Updates.

Advisory: The opera package prior to 12.11 contains several security problems:

* HTTP response heap buffer overflow can allow execution of arbitrary code.
  http://www.opera.com/support/kb/view/1036/

* Error pages can be used to guess local file paths.
  http://www.opera.com/support/kb/view/1037/

Opera has been updated to 12.11 to fix above problems.

https://bugs.mageia.org/show_bug.cgi?id=8162
Comment 2 Thomas Backlund 2012-11-21 21:09:37 CET
Update pushed:
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0337
Comment 3 James Kerr 2012-11-26 05:36:23 CET
Opera 12.11 needs to be pushed from testing to updates on Mageia 2. (It has been pushed on Mageia 1 only.)
Comment 4 claire robinson 2012-11-26 10:39:52 CET
Confirmed.

$ ./depcheck opera
Mageia release 2 (Official) for x86_64
------------------
Nonfree Release
opera-11.64-1.mga2.nonfree
------------------
Nonfree Updates
opera-12.00-1.1.mga2.nonfree
opera-12.01-1.mga2.nonfree
opera-12.02-1.mga2.nonfree
opera-12.10-1.1.mga2.nonfree
------------------
Nonfree Updates Testing
opera-12.11-1.mga2.nonfree
------------------
Comment 5 Thomas Backlund 2012-11-26 15:16:27 CET
Oops. Sorry about that, and thanks for notifying us.

opera-12.11 pushed for Mga2

Note You need to log in before you can comment on or make changes to this bug.