The CSS functionality in Opera 9 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the background property of a DHTML element to a long http or https URL, which triggers memory corruption.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/27977 | vdb entry third party advisory |
http://browserfun.blogspot.com/2006/07/mobb-26-opera-css-background.html | broken link exploit |
http://www.osvdb.org/27374 | exploit vdb entry broken link |
http://www.vupen.com/english/advisories/2006/2987 | vdb entry broken link |