Don't know why I am not configured to receive PMs but I didn't find an option.
However I found the php exploit on the web.
I was not able to make it run on my localhost. Not sure if there are any requirements.
Regarding the DoS problem, thats not a security issue in my opinion, more a stability issue. You won't be compromised that way.
Edit: haavard posted yet another message:
Twitter / Haavard: Our devs have looked furth ...
Interesting. Thanks for the information.
Not sure if you're still following this thread, or the one over on the Opera boards, but someone dropped a link to a PoC exploit that made some of the user's anti-virus go nuts. Since the intrusion in question was labeled as a Trojan, and since the vulnerability itself is too new to have been picked up by A/V vendors, it's a good bet that someone was using this new exploit to distribute old malware. I'd say remote code execution is possible and confirmed.
My Computer
- Computer Manufacturer/Model Number
- Custom
- OS
- Windows 7 RTM
- CPU
- i7 920
- Motherboard
- eVGA x58 SLi
- Memory
- 6 GB Patriot
- Graphics Card(s)
- eVGA GeForce 275 GTX
- Sound Card
- Soundblaster X-Fi Gamer
- Monitor(s) Displays
- Acer 225Tw
- Hard Drives
- WD 1 TB
- PSU
- Corsair 750 W
- Case
- Antec Twelve Hundred
- Cooling
- Stock