Bugzilla – Bug 188632
Opera 9.0 denial of service with A tag.
Last modified: 2009-10-13 22:09:33 UTC
This is public. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3199 Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which triggers an out-of-bounds operation. Note that this will not stop the current update, it will just wait for a fix from Opera.
Fixed in Opera 9.01, updating autobuild http://www.opera.com/support/search/supsearch.dml?index=835
Looks like opera sw does not consider this a security issue therefore we shouldn't either. Just fix it for stable then.
Done
*** Bug 199378 has been marked as a duplicate of this bug. ***
CVE-2006-3199: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)