Opera 9.64 - сервисный релиз универсального кросс-платформенного браузера
Разработчики одноименного норвежского браузера из компании Opera Software выпустили очередную стабильную версию своей программы. Браузер использует собственный движок для прорисовки web-страниц, который является одним из самых быстрых по сравнению с конкурентами (Firefox, Internet Explorer и прочими). Объединяет под одной оболочной фактически несколько «отдельных» приложений, среди них: почтовый клиент, RSS-клиент, IRC-клиент BitTorrent-клиент и собственно сам браузер. Присутствует так же многоязычная версия инсталлятора, в которую включен русский интерфейс.
We released 9.64 today. This release is a recommended security upgrade for all those running the latest stable releases.
Starting with this release, Opera on Windows supports the security measures "Data Execution Prevention (DEP)" (available in Windows XP SP2 and newer) and "Address Space Layout Randomization (ASLR)" (available in Vista and newer).
These security measures are a kind of second line of defence once an application runs into a serious fault, which would normally cause it to crash sooner or later. Of course that should just not happen in the first place, but you can never completely rule out programming errors. Depending on the exact nature of the fault, an attacker can sometimes exploit it and try to take over your system. DEP and ASLR make that a lot harder.
Changes and improvements since Opera 9.63
Security
* Fixed an issue where specially crafted JPEG images ccould be used to execute arbitrary code, as reported by Tavis Ormandy of the Google Security Team; see our advisory * Fixed an issue where plug-ins could be used to allow cross domain scripting, as reported by Adam Barth; details will be disclosed at a later date. * Fixed a moderately severe issue; details will be disclosed at a later date. * Added support for the following platform-specific features: o DEP (Data Execution Prevention) in Microsoft WindowsXP® with Service Pack 2 and higher and Microsoft Windows Server 2003® with Service Pack 1 o ASLR (Address Space Layout Randomization) in Microsoft Windows Vista® * Added Untrusted Rootstore Capability: o Opera downloads only the detailed information about untrusted (blacklisted) certificates when they are encountered o If download fails for certificate information in the list, Opera considers any certificate matching the ID as untrusted * Added version conditional fetching of certificate dependencies from an online repository * Fixed a problem downloading the CRL (Certificate Revocation List) * Fixed a problem that could cause SSL to deadlock in one state, hanging the connection * Fixed a problem that could cause the incorrect calculation of Certificate IDs * Implemented Extended Validation (EV) for cross-signed EV Root Certificates not shipped by default * Implemented preshipping of the Entrust 2048 CA (Certificate Authority) * Implemented Root Certificate fetching from an online repository when an intermediate matches a certificate in the repository * Improved support for weak encryption when importing .p12 private certificates * Prevented security information documents from being written to disk
Miscellaneous
* Fixed a problem which created separate feed notifications; Opera now groups them together * Fixed a problem with inline find when no content was entered and the Enter key was pressed * Implemented opacity on text styled with hexidecimal color codes * Installing an external source viewer no longer requires an Opera restart * Installing Opera sets it as the default browser; this may be reset during the install process
|