First published: Tue Aug 07 2012(Updated: )
Multiple heap-based buffer overflow flaws were found in the way the Base64 decoder of libotr, an Off-The-Record Messaging library and toolkit, performed decoding of certain messages. A remote attacker could provide a specially-crafted OTR message that once processed in an application linked against libotr would lead to that application crash or, potentially, arbitrary code execution with the privileges of the user running the application. References: [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684121">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684121</a> [2] <a href="http://lists.cypherpunks.ca/pipermail/otr-dev/2012-July/001347.html">http://lists.cypherpunks.ca/pipermail/otr-dev/2012-July/001347.html</a> Relevant upstream patches: [3] <a href="http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr;a=commitdiff;h=b17232f86f8e60d0d22caf9a2400494d3c77da58">http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr;a=commitdiff;h=b17232f86f8e60d0d22caf9a2400494d3c77da58</a> [4] <a href="http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr;a=commitdiff;h=6d4ca89cf1d3c9a8aff696c3a846ac5a51f762c1">http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr;a=commitdiff;h=6d4ca89cf1d3c9a8aff696c3a846ac5a51f762c1</a> [5] <a href="http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr;a=commitdiff;h=1902baee5d4b056850274ed0fa8c2409f1187435">http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr;a=commitdiff;h=1902baee5d4b056850274ed0fa8c2409f1187435</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cypherpunks Libotr | <=3.2.0 | |
Cypherpunks Libotr | =3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.