A problem in Opera 9.2 could allow a malicious torrent to cause the execution of arbitrary code with the local user's privileges.
iDefense Labs confirmed the issue in Opera 9.21. Someone who clicks a link to download a specially crafted BitTorrent file through Opera's native file transfer could be victimized.
The iDefense advisory described the specifics of the problem:
When parsing a specially crafted BitTorrent header, Opera uses memory that has already been freed. This can result in an invalid object pointer being dereferenced, and may allow for the execution of arbitrary code. The vulnerability is triggered when the user right clicks on the transfer and removes it.
Opera has since released Opera 9.22 with a fix for the problem in place.
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.