<?xml version="1.0"?>
<?xml-stylesheet href="../fma_report_en.xslt" type="text/xsl" ?>

<advisory xml:space="preserve">
	<meta>
		<description>Opera Browser 12.00 SVG filter element Denial of Service</description>
		<keywords>fuzzing, security, blackbox, tests, Opera, DoS, SVG</keywords>
	</meta>

	<title>Opera Browser SVG filter element Denial of Service</title>
	<id>FMA-2012-015</id>
	
	<refs>
		<ref>
			<name>DSK</name>
			<id>DSK-368718</id>
		</ref>	
	</refs>
	
	<application>
		<name>Opera</name>
		<version>12.00</version>
		<url>http://www.opera.com</url>
		<files>
			<file>
				<name>Opera.dll</name>
				<version>12.0.1454.0</version>
				<md5>81311d2b76a32e913a721ba9eab93b48</md5>
			</file>
		</files>		
		<verified>
			<os>
				<name>Windows XP SP3 Home Edition</name>
			</os>
			<os>
				<name>Windows 7 SP1 Home Premium</name>
			</os>
		</verified>
	</application>
	
	<discovery>
		<found>2012.06.15</found>
		<vendor_notified>2012.06.28</vendor_notified>
		<published>2012.08.08</published>
	</discovery>
	
	<vulnerabilities>
		<vulnerability>
			<name>Opera Browser null pointer dereference.</name>
			<type>DoS</type>
			<description>Calling group of functions on SVG filter object raises access violation exception because of null pointer dereference.</description>
			<exception>Access violation exception.</exception>
<disasm>6A555612  |.-/0F84 F32B0000 JE 6A55820B
6A555618  |. |8B09          MOV ECX,DWORD PTR DS:[ECX]
6A55561A  |. |F741 1C FF010 TEST DWORD PTR DS:[ECX+1C],000001FF      ; [FuzzMyApp.com] Access violation when reading
6A555621  |.-|0F84 E42B0000 JE 6A55820B</disasm>
			<images>
				<image>
					<thumbnail>
						<src>image01s.png</src>
						<width>100</width>
						<height>65</height>
					</thumbnail>
					<src>image01.png</src>
					<alt>Access violation when reading</alt>
					<text>Access violation when reading</text>
				</image>
			</images>
		</vulnerability>	
	</vulnerabilities>
</advisory>