Packages
- libotr - Off-the-Record Messaging library
Details
Justin Ferguson discovered multiple heap overflows in libotr. A remote
attacker could use this to craft a malformed OTR message that could
cause a denial of service via application crash or possibly execute
arbitrary code.
Justin Ferguson discovered multiple heap overflows in libotr. A remote
attacker could use this to craft a malformed OTR message that could
cause a denial of service via application crash or possibly execute
arbitrary code.
Update instructions
After a standard system update you need to restart any instant messaging applications using an Off-the-Record messaging plugin to make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
12.04 precise | libotr2 – 3.2.0-4ubuntu0.1 | ||
11.10 oneiric | libotr2 – 3.2.0-2.1ubuntu0.1 | ||
11.04 natty | libotr2 – 3.2.0-2ubuntu1.1 | ||
10.04 lucid | libotr2 – 3.2.0-2ubuntu0.1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.