OESF Portables Forum

Everything Else => General Support and Discussion => Zaurus General Forums => Archived Forums => Security and Networking => Topic started by: dsavard on December 08, 2004, 11:22:28 pm

Title: Vulnerability In Opera
Post by: dsavard on December 08, 2004, 11:22:28 pm
Secunia has reported a vulnerability which affect all web browsers, including Opera. There is also a story on /.

I checked and this vulnerability exists on the Opera version shipped with the Z6K (7.25). It seems latest version of Opera is not vulnerable (7.54).

Anybidy knows how Opera can be upgraded on the Zaurus and if there is a cost?
Title: Vulnerability In Opera
Post by: Jcroto1 on December 09, 2004, 05:01:21 pm
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
Title: Vulnerability In Opera
Post by: maslovsky on December 22, 2004, 03:22:37 am
Quote
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
No, it's not.
Title: Vulnerability In Opera
Post by: Jcroto1 on December 22, 2004, 01:26:52 pm
Quote
Quote
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
No, it's not.
Yes, it's in the /home/zaurus/.opera directory (if you were to extract it) and it's called "opera_arm.ipk"
[span style=\'font-size:8pt;line-height:100%\']look in the postinst[/span]
Title: Vulnerability In Opera
Post by: Greg2 on December 24, 2004, 11:20:45 am
Quote
Quote
Quote
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
No, it's not.
Yes, it's in the /home/zaurus/.opera directory (if you were to extract it) and it's called "opera_arm.ipk"
[span style=\'font-size:8pt;line-height:100%\']look in the postinst[/span]
I'm in the process of repackaging this for my 5500 and 5600 with oz3.5.2 and this is the control file from the opera.ipk in the multimodal_arm.ipk:

Package: opera
Version: 7.55.6079
Architecture: arm
Maintainer: Stein Kulseth <steink@opera.com>
Priority: optional
Section: web
Description: The Opera Web Browser
 Welcome to the Opera Web browser. It is smaller, faster,
 customizable, powerful, yet user-friendly. Opera eliminates
 sluggish performance, HTML standard violations, desktop
 domination, and instability. This robust Web browser lets you
 navigate the Web at incredible speed and offers you the best
 Internet experience.

With a little effort this should work on a 6000?

Greg
Title: Vulnerability In Opera
Post by: Jcroto1 on December 24, 2004, 03:57:47 pm
It should work with no effort.  When you download it it says it's for the 5600 and 6000.  So hopefully eveything will work without tweaking.
Title: Vulnerability In Opera
Post by: maslovsky on December 24, 2004, 04:07:33 pm
Quote
Quote
Quote
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
No, it's not.
Yes, it's in the /home/zaurus/.opera directory (if you were to extract it) and it's called "opera_arm.ipk"
[span style=\'font-size:8pt;line-height:100%\']look in the postinst[/span]
What I mean is that Opera is there in the package but that version is still affected by the vulnerability...
Title: Vulnerability In Opera
Post by: grog on January 01, 2005, 03:31:52 pm
Quote
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
I registered, downloaded & extracted & installed the opera_arm.ipk, and ipkg shows it's installed, but there's still no application icon, even after a reboot. Anybody know what else I need to do? thks
Title: Vulnerability In Opera
Post by: JohnKiniston on January 01, 2005, 04:12:41 pm
Quote
Quote
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
I registered, downloaded & extracted & installed the opera_arm.ipk, and ipkg shows it's installed, but there's still no application icon, even after a reboot. Anybody know what else I need to do? thks
Which rom are you using?

Did you use ipkg-link to link it to root if you installed it on SD or CF?
Title: Vulnerability In Opera
Post by: grog on January 02, 2005, 12:05:48 pm
Quote
Quote
Quote
Opera 7.55 is burried in the WebSphere Everyplace Multimodal Environment package.  It's free but you have to register first.

http://www14.software.ibm.com/webapp/downl...p?go=y&rs=wsmee (http://www14.software.ibm.com/webapp/download/search.jsp?go=y&rs=wsmee)

Hope it has the patch.
I registered, downloaded & extracted & installed the opera_arm.ipk, and ipkg shows it's installed, but there's still no application icon, even after a reboot. Anybody know what else I need to do? thks
Which rom are you using?

Did you use ipkg-link to link it to root if you installed it on SD or CF?
I installed to my internal memory not to a card, so I'm assuming that ipkg-link isn't required? As for what ROM, it's OPIE-OZ 3.5.2 - I've seen discussions of other 'types', but how can I tell which one I'm using? And where to I get the different types? There was only the one set
here (http://www.openzaurus.org/official/unstable/3.5.2/sl5600/).
Title: Vulnerability In Opera
Post by: Jcroto1 on January 02, 2005, 12:48:22 pm
Quote
What I mean is that Opera is there in the package but that version is still affected by the vulnerability...
Ahh.  Ok.  It makes sense.
Title: Vulnerability In Opera
Post by: Jcroto1 on January 02, 2005, 12:56:49 pm
grog,

This Opera installs all the packages to /home/QtPalmtop/bin but OZ looks in the /opt/QtPalmtop/bin.  You have to symlink it all by hand,
Code: [Select]
ln -s /home/QtPalmtop/bin/opera /opt/QtPalmtop/bin/opera
ln -s ...

PS  I found this version to be very unstable which I just wanted to tell you before you spent the time fixing it

Have fun!!
Title: Vulnerability In Opera
Post by: grog on January 03, 2005, 08:44:32 pm
Quote
PS  I found this version to be very unstable which I just wanted to tell you before you spent the time fixing it
Thanks for the tip. So what is the best *STABLE* version of opera then? 6 or 7.3 seem to be the other two available AFAIK. thks
Title: Vulnerability In Opera
Post by: JohnKiniston on January 03, 2005, 11:34:59 pm
Quote
Quote
PS  I found this version to be very unstable which I just wanted to tell you before you spent the time fixing it
Thanks for the tip. So what is the best *STABLE* version of opera then? 6 or 7.3 seem to be the other two available AFAIK. thks
6 seems to be the best version under OpenZaurus 3.5.2 from my experience.

7.x seemed slower and crashed a lot more often.

I still have problems with 6 loading blank pages at times.
Title: Vulnerability In Opera
Post by: grog on January 04, 2005, 06:22:41 am
Quote
6 seems to be the best version under OpenZaurus 3.5.2 from my experience.

7.x seemed slower and crashed a lot more often.

I still have problems with 6 loading blank pages at times.
I've noticed that with 7.3 too. I'm going to try going back to 6 for a while & see if that's better for me. I don't know what's supposed to make 7.X worth while, but for my simple needs I doubt I'll be missing anything :?).

thanks again
Title: Vulnerability In Opera
Post by: dougeeebear on January 04, 2005, 03:25:05 pm
Quote
Secunia has reported a vulnerability which affect all web browsers, including Opera.
I am running Opera 7.55 on SL-5500 using standard Sharp Rom 3.13 and it works perfectly.

Exactly what is this vulnerability you are talking about?

Doug
Title: Vulnerability In Opera
Post by: technojunkie on January 06, 2005, 02:03:30 pm
The vulnerability allows someone to spoof a dialog box that opens in a new tab. Personally I see the risk as being a bit negligible. As long as you are aware of it It shouldn't be too difficult to avoid.
Title: Vulnerability In Opera
Post by: grog on January 07, 2005, 09:55:55 pm
Quote
This Opera installs all the packages to /home/QtPalmtop/bin but OZ looks in the /opt/QtPalmtop/bin.  You have to symlink it all by hand,
Code: [Select]
ln -s /home/QtPalmtop/bin/opera /opt/QtPalmtop/bin/opera
ln -s ...
I still wanted to try 7.55 & I finally got some time, so after I installed the package I ran this:

Code: [Select]
ipkg files opera | while read file; do case $file in *home*) ln -s $file /opt/${file#*home/};; esac; doneThen I ran makecompat & now I have Opera 7.55 running. Hope that helps somebody else. havefun!!
Title: Vulnerability In Opera
Post by: grog on January 11, 2005, 11:50:15 am
Quote
... now I have Opera 7.55 running.
And after a while now I've gone back to opera6. I guess I just had to see for myself, but yes 6 is a lot faster than the 7's, and the 7's seem to crash an awful lot. FYI
Title: Vulnerability In Opera
Post by: Flandry on January 11, 2005, 05:48:16 pm
I guess that answers my question regarding why cacko 1.22 included an older version of the browser.  It sure seems to me that there's enough to fix that it should be easy to make an improvement from 7.25 to 7.55.  Unfortunate.

Does anyone know how to adjust the cache of opera so that it doesn't leak memory until it has to be closed and restarted?  I assume that's where all the memroy is going, anyway.  The blank page loading thing is annoying, too.  At least it makes much better use out of a small screen than netfront.
Title: Vulnerability In Opera
Post by: dougeeebear on January 11, 2005, 07:41:57 pm
**DELETED**