Oval Definition:oval:org.mitre.oval:def:18429
Revision Date:2014-06-23Version:7
Title:DSA-2526-1 libotr - buffer overflow
Description:Just Ferguson discovered that libotr, an off-the-record (OTR) messaging library, can be forced to perform zero-length allocations for heap buffers that are used in base64 decoding routines. An attacker can exploit this flaw by sending crafted messages to an application that is using libotr to perform denial of service attacks or potentially execute arbitrary code.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-3461
DSA-2526-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):libotr
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND libotr DPKG is earlier than 3.2.0-2+squeeze1
  • BACK