[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2526-1 libotr -- heap-based buffer overflows

ID: oval:org.secpod.oval:def:600865Date: (C)2012-08-14   (M)2023-02-20
Class: PATCHFamily: unix




Just Ferguson discovered that libotr, an off-the-record messaging library, can be forced to perform zero-length allocations for heap buffers that are used in base64 decoding routines. An attacker can exploit this flaw by sending crafted messages to an application that is using libotr to perform denial of service attacks or potentially execute arbitrary code.

Platform:
Debian 6.0
Product:
libotr2
libotr2-dev
libotr2-bin
Reference:
DSA-2526-1
CVE-2012-3461
CVE    1
CVE-2012-3461
CPE    4
cpe:/a:cypherpunks:libotr2-bin
cpe:/a:cypherpunks:libotr2-dev
cpe:/a:cypherpunks:libotr2
cpe:/o:debian:debian_linux:6.0
...

© SecPod Technologies