Oval Definition:oval:org.cisecurity:def:601
Revision Date:2016-07-01Version:6
Title:DSA-3512-1 -- libotr -- security update
Description:Markus Vervier of X41 D-Sec GmbH discovered an integer overflow vulnerability in libotr, an off-the-record (OTR) messaging library, in the way how the sizes of portions of incoming messages were stored. A remote attacker can exploit this flaw by sending crafted messages to an application that is using libotr to perform denial of service attacks (application crash), or potentially, execute arbitrary code with the privileges of the user running the application.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2016-2851
DSA-3512-1
Platform(s):Debian 8
Debian GNU/kFreeBSD 7
Debian GNU/Linux 7
Product(s):libotr
Definition Synopsis
  • Debian 7
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND libotr is earlier than 0:3.2.1-1+deb7u2
  • OR Debian 8
  • Debian 8 is installed
  • AND libotr is earlier than 0:4.1.0-2+deb8u1
  • BACK