Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Multiple vulnerabilities have been found in libotr and Pidgin OTR, allowing remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201701-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libotr, Pidgin OTR: Remote execution of arbitrary code Date: January 02, 2017 Bugs: #576914, #576916 ID: 201701-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libotr and Pidgin OTR, allowing remote attackers to execute arbitrary code. Background ========= Pidgin Off-the-Record (OTR) messaging allows you to have private conversations over instant messaging. libotr is a portable off-the-record messaging library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/libotr < 4.1.1 > = 4.1.1 2 x11-plugins/pidgin-otr < 4.0.2 > = 4.0.2 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities exist in both libotr and Pidgin OTR. Please review the CVE identifiers for more information. Impact ===== A remote attacker could send a specially crafted message, possibly resulting in the execution of arbitrary code with the privileges of the process, or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All libotr users should upgrade to the latest version: # emerge --sync # emerge --ask--oneshot --verbose "> =net-libs/libotr-4.1.1" All Pidgin OTR users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-plugins/pidgin-otr-4.0.2" References ========= [ 1 ] CVE-2015-8833 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8833 [ 2 ] CVE-2016-2851 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2851 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201701-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Updated to 4.1.1 for CVE-2016-2851. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-2982f06845 2016-03-27 00:00:51.401335 -------------------------------------------------------------------------------- Name : libotr Product : Fedora 24 Version : 4.1.1 Release : 1.fc24 URL : https://otr.cypherpunks.ca/ Summary : Off-The-Record Messaging library and toolkit Description : Off-the-Record Messaging Library and Toolkit This is a library and toolkit which implements Off-the-Record (OTR) Messaging. OTR allows you to have private conversations over IM by providing Encryption, Authentication, Deniability and Perfect forward secrecy. -------------------------------------------------------------------------------- Update Information: Updated to 4.1.1 for CVE-2016-2851 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1315247 https://bugzilla.redhat.com/show_bug.cgi?id=1315247 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libotr' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated to 4.1.1 for CVE-2016-2851. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-8b4f643f3d 2016-03-19 22:17:41.317114 -------------------------------------------------------------------------------- Name : libotr Product : Fedora 23 Version : 4.1.1 Release : 1.fc23 URL : https://otr.cypherpunks.ca/ Summary : Off-The-Record Messaging library and toolkit Description : Off-the-Record Messaging Library and Toolkit This is a library and toolkit which implements Off-the-Record (OTR) Messaging. OTR allows you to have private conversations over IM by providing Encryption, Authentication, Deniability and Perfect forward secrecy. -------------------------------------------------------------------------------- Update Information: Updated to 4.1.1 for CVE-2016-2851 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1315247 https://bugzilla.redhat.com/show_bug.cgi?id=1315247 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libotr' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated to 4.1.1 for CVE-2016-2851. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-fde759f627 2016-03-19 21:03:15.515452 -------------------------------------------------------------------------------- Name : libotr Product : Fedora 22 Version : 4.1.1 Release : 1.fc22 URL : https://otr.cypherpunks.ca/ Summary : Off-The-Record Messaging library and toolkit Description : Off-the-Record Messaging Library and Toolkit This is a library and toolkit which implements Off-the-Record (OTR) Messaging. OTR allows you to have private conversations over IM by providing Encryption, Authentication, Deniability and Perfect forward secrecy. -------------------------------------------------------------------------------- Update Information: Updated to 4.1.1 for CVE-2016-2851 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1315247 https://bugzilla.redhat.com/show_bug.cgi?id=1315247 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libotr' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libotr,libotr2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:0708-1 Rating: important References: #969785 Cross-References: CVE-2016-2851 Affected Products: openSUSE Leap 42.1 openSUSE 13.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: libotr and libotr2 were updated to fix one security issue: - CVE-2016-2851: Integer overflow vulnerability allowed remote attackers to execute arbitrary code on 64 bit platforms (boo#969785) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2016-322=1 - openSUSE 13.2: zypper in -t patch openSUSE-2016-322=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.1 (i586 x86_64): libotr-debugsource-4.1.1-4.1 libotr-devel-4.1.1-4.1 libotr-tools-4.1.1-4.1 libotr-tools-debuginfo-4.1.1-4.1 libotr2-3.2.1-13.1 libotr2-debuginfo-3.2.1-13.1 libotr2-debugsource-3.2.1-13.1 libotr2-devel-3.2.1-13.1 libotr2-tools-3.2.1-13.1 libotr2-tools-debuginfo-3.2.1-13.1 libotr5-4.1.1-4.1 libotr5-debuginfo-4.1.1-4.1 - openSUSE 13.2 (i586 x86_64): libotr-debugsource-4.0.0-8.3.1 libotr-devel-4.0.0-8.3.1 libotr-tools-4.0.0-8.3.1 libotr-tools-debuginfo-4.0.0-8.3.1 libotr2-3.2.1-7.3.1 libotr2-debuginfo-3.2.1-7.3.1 libotr2-debugsource-3.2.1-7.3.1 libotr2-devel-3.2.1-7.3.1 libotr2-tools-3.2.1-7.3.1 libotr2-tools-debuginfo-3.2.1-7.3.1 libotr5-4.0.0-8.3.1 libotr5-debuginfo-4.0.0-8.3.1 References: https://www.suse.com/security/cve/CVE-2016-2851.html https://bugzilla.suse.com/969785 . Important patch for openSUSE resolving buffer overflow in libotr, strengthening protection against external threats.. openSUSE Security, libotr security patch, integer overflow fix. . Severity: Important. LinuxSecurity.com Team
Markus Vervier of X41 D-Sec GmbH discovered an integer overflow vulnerability in libotr, an off-the-record (OTR) messaging library, in the way how the sizes of portions of incoming messages were stored. A remote attacker can exploit this flaw by sending crafted messages to an . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3512-1
Applications using the OTR secure chat protocol could be made to exposesensitive information over the network.. =========================================================================Ubuntu Security Notice USN-2091-1 January 29, 2014 libotr vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Applications using the OTR secure chat protocol could be made to expose sensitive information over the network. Software Description: - libotr: Off-the-Record Messaging library Details: This update disables the OTR v1 protocol to prevent protocol downgrade attacks. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libotr2 3.2.0-4ubuntu0.2 After a standard system update you need to restart OTR applications to make all the necessary changes. References: https://bugs.launchpad.net/ubuntu/+source/libotr/+bug/1266016 Package Information: https://launchpad.net/ubuntu/+source/libotr/3.2.0-4ubuntu0.2 . Applying security patches for OTR vulnerabilities in Ubuntu 12.04 LTS is essential to protect sensitive data transmitted over networks and reduce risks. OTR Protocol, Ubuntu Security, libotr Library, Network Security, Sensitive Data Leakage. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: update for libotr ______________________________________________________________________________ Announcement ID: openSUSE-SU-2013:0155-1 Rating: important References: #789190 Cross-References: CVE-2012-3461 Affected Products: openSUSE 11.4/standard/i586/patchinfo.12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update of libotr fixed multiple buffer overflows. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4/standard/i586/patchinfo.12: zypper in -t patch 2012-8 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4/standard/i586/patchinfo.12 (i586 x86_64): libotr-debugsource-3.2.1-11.1 libotr-devel-3.2.1-11.1 libotr-tools-3.2.1-11.1 libotr-tools-debuginfo-3.2.1-11.1 libotr2-3.2.1-11.1 libotr2-debuginfo-3.2.1-11.1 References: https://www.suse.com/security/cve/CVE-2012-3461.html -- . This crucial notification pertains to a memory leak issue in libotr for openSUSE, bolstering overall system integrity.. openSUSE Security, Libotr Patch, Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.