LWN.net Logo

libotr: code execution

Package(s):libotr CVE #(s):CVE-2012-3461
Created:August 13, 2012 Updated:April 10, 2013
Description: From the Debian advisory:

Just Ferguson discovered that libotr, an off-the-record (OTR) messaging library, can be forced to perform zero-length allocations for heap buffers that are used in base64 decoding routines. An attacker can exploit this flaw by sending crafted messages to an application that is using libotr to perform denial of service attacks or potentially execute arbitrary code.

Alerts:
Debian DSA-2526-1 2012-08-12
Mandriva MDVSA-2012:131 2012-08-13
Ubuntu USN-1541-1 2012-08-16
Mageia MGASA-2012-0223 2012-08-18
Fedora FEDORA-2012-11959 2012-08-25
Fedora FEDORA-2012-11934 2012-08-25
openSUSE openSUSE-SU-2012:1525-1 2012-11-22
SUSE SUSE-SU-2012:1578-1 2012-11-28
openSUSE openSUSE-SU-2013:0155-1 2013-01-23
Mandriva MDVSA-2013:097 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds