Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Applications using the OTR secure chat protocol could be made to expose
sensitive information over the network.
Software Description:
- libotr: Off-the-Record Messaging library
Details:
This update disables the OTR v1 protocol to prevent protocol downgrade
attacks.
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libotr2 3.2.0-4ubuntu0.2 After a standard system update you need to restart OTR applications to make all the necessary changes.
https://bugs.launchpad.net/ubuntu/+source/libotr/+bug/1266016
Get the latest Linux and open source security news straight to your inbox.