Security:
News ToolsReg Shops |
Torrent overflows OperaBrowser maker lances file download bugPublished Wednesday 23rd May 2007 10:49 GMT Opera has fixed a flawed involving how its browser handles Torrent files that allowed hackers to attack vulnerable systems. A boundary error in handling certain types of Torrent files exposed version 9.x of the browser to a stack-based buffer overflow, providing a user right-clicks a malicious Torrent entry in the transfer manager. Simply clicking on the Torrent link will not trigger the flaw, which Opera nonetheless describes as "highly critical". Successful exploitation creates a means for hackers to inject hostile code. The flaw, discovered by security researchers at iDefense, has been confirmed in Opera version 9.20 for Windows. Other versions may also be affected. Users are advised to upgrade to Opera version 9.21 to guard against attack. Opera has included a built-in BitTorrent client in its browser software since the release of version 9.0, last June. ® 5 comments posted — Comment period finished How many is that this year?Posted: 13:42 23rd May 2007 Patched alreadyPosted: 15:18 23rd May 2007 Speedy patchPosted: 16:22 23rd May 2007 ..and so quickPosted: 17:06 23rd May 2007 Just to confirm how good Opera is...Posted: 07:56 24th May 2007
Track this type of story as a custom Atom/RSS feed or by email.
|
|
Top 20 stories • All The Week’s Headlines • Archive • Search