LWN.net Logo

Mageia alert MGASA-2012-0223 (libotr)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2012-0223: libotr-3.2.0-5.2.mga (1, 2/core)
Date:  Sat, 18 Aug 2012 12:11:46 +0200
Message-ID:  <20120818101146.GA16387@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2012-0223 Date: August 18th, 2012 Affected releases: 1, 2 Description: Updated libotr packages fix security vulnerability: Just Ferguson discovered that libotr, an off-the-record (OTR) messaging library, can be forced to perform zero-length allocations for heap buffers that are used in base64 decoding routines. An attacker can exploit this flaw by sending crafted messages to an application that is using libotr to perform denial of service attacks or potentially execute arbitrary code (CVE-2012-3461) Updated Packages: Mageia 1: lib(64)otr2-3.2.0-5.2.mga1 lib(64)otr-devel-3.2.0-5.2.mga1 libotr-utils-3.2.0-5.2.mga1 Mageia 2: lib(64)otr2-3.2.0-5.2.mga2 lib(64)otr-devel-3.2.0-5.2.mga2 libotr-utils-3.2.0-5.2.mga2 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3461 http://www.mandriva.com/en/support/security/advisories/?d... https://bugs.mageia.org/show_bug.cgi?id=7043 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds