Release date:
Updated on: 2012-09-06
Affected Systems:
Debian Linux 6.0 x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54907
Cve id: CVE-2012-3461
Debian is a popular Linux release version.
Multiple heap buffer overflow vulnerabilities exist in libotr2 3.2.1 and the functions otrl_base64_otr_decode and src/proto in src/b64.c. in c, otrl_proto_data_read_flags, otrl_proto_accept_data, toolkit/parse. the decode function in c allocates a zero-byte buffer when decoding the base64 string, allowing remote attackers to pass "? OTR: =. "message causes a denial of service, triggering heap buffer overflow.
<* Source: Just Ferguson
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Debian
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.debian.org/security/