Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 12.04 LTS: 1541-1 Critical: libotr Heap Overflow

ubuntu
Calendar Grey August 16, 2012
Scroller Ubuntu
Discover the serious libotr flaw impacting various Ubuntu versions and understand the best strategies to address it promptly.
Applications using Off-the-Record messaging plugins could be madeto crash or run programs if it received specially crafted networkmessages.

Summary

Applications using Off-the-Record messaging plugins could be made

to crash or run programs if it received specially crafted network

messages.

Software Description:

- libotr: Off-the-Record Messaging library

Details:

Justin Ferguson discovered multiple heap overflows in libotr. A remote

attacker could use this to craft a malformed OTR message that could

cause a denial of service via application crash or possibly execute

arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  libotr2                         3.2.0-4ubuntu0.1

Ubuntu 11.10:
  libotr2                         3.2.0-2.1ubuntu0.1

Ubuntu 11.04:
  libotr2                         3.2.0-2ubuntu1.1

Ubuntu 10.04 LTS:
  libotr2                         3.2.0-2ubuntu0.1

After a standard system update you need to restart any instant
messaging applications using an Off-the-Record messaging plugin to
make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1541-1

CVE-2012-3461

Severity
critical
Lowest
Low
Medium
High
Critical

August 16, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.