[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Pidgin - (bulletinapr2017)

ID: oval:org.secpod.oval:def:2101117Date: (C)2019-12-28   (M)2023-02-20
Class: PATCHFamily: unix




The (1) otrl_base64_otr_decode function in src/b64.c; (2) otrl_proto_data_read_flags and (3) otrl_proto_accept_data functions in src/proto.c; and (4) decode function in toolkit/parse.c in libotr before 3.2.1 allocates a zero-length buffer when decoding a base64 string, which allows remote attackers to cause a denial of service (application crash) via a message with the value "?OTR:===.", which triggers a heap-based buffer overflow.

Platform:
Sun Solaris 11
Product:
entire
Reference:
bulletinapr2017
CVE-2012-3461
CVE-2012-2369
CVE    2
CVE-2012-2369
CVE-2012-3461
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies