CVE-2007-6524: Infoleak
Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6524?
CVE-2007-6524 is considered a medium severity vulnerability due to its potential to leak sensitive memory contents.
How do I fix CVE-2007-6524?
The recommended fix for CVE-2007-6524 is to upgrade to Opera version 9.25 or later.
What impact does CVE-2007-6524 have on affected systems?
CVE-2007-6524 allows remote attackers to potentially gain access to sensitive data from memory via crafted bitmap files.
Which versions of Opera are affected by CVE-2007-6524?
CVE-2007-6524 affects Opera versions prior to 9.25 as well as several early versions including 5.0 up to 9.24.
Is there a workaround for CVE-2007-6524 if I can't update?
While updating is the best solution, users may try disabling JavaScript to mitigate the risk temporarily.