Vulnerability Bulletins

DSA-3512 libotr - security update

   
Affected software Debian
 
Markus Vervier of X41 D-Sec GmbH discovered an integer overflowvulnerability in libotr, an off-the-record (OTR) messaging library, inthe way how the sizes of portions of incoming messages were stored. Aremote attacker can exploit this flaw by sending crafted messages to anapplication that is using libotr to perform denial of service attacks(application crash), or potentially, execute arbitrary code with theprivileges of the user running the application.

More info:

https://www.debian.org/security/2016/dsa-3512