Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.71841
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: libotr
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: libotr

CVE-2012-3461
The (1) otrl_base64_otr_decode function in src/b64.c, (2)
otrl_proto_data_read_flags and (3) otrl_proto_accept_data functions in
src/proto.c, and (4) decode function in toolkit/parse.c in libotr
before 3.2.1 allocates a zero-length buffer when decoding a base64
string, which allows remote attackers to cause a denial of service
(application crash) via a message with the value '?OTR:===.', which
triggers a heap-based buffer overflow.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-3461
54907
http://www.securityfocus.com/bid/54907
DSA-2526
http://www.debian.org/security/2012/dsa-2526
MDVSA-2012:131
http://www.mandriva.com/security/advisories?name=MDVSA-2012:131
MDVSA-2013:097
http://www.mandriva.com/security/advisories?name=MDVSA-2013:097
SUSE-SU-2012:1578
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00019.html
USN-1541-1
http://www.ubuntu.com/usn/USN-1541-1
[OTR-dev] 20120727 Re: otrl_base64_otr_decode() function...
http://lists.cypherpunks.ca/pipermail/otr-dev/2012-July/001348.html
[OTR-dev] 20120727 otrl_base64_otr_decode() function...
http://lists.cypherpunks.ca/pipermail/otr-dev/2012-July/001347.html
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684121
http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr%3Ba=commitdiff%3Bh=1902baee5d4b056850274ed0fa8c2409f1187435
http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr%3Ba=commitdiff%3Bh=6d4ca89cf1d3c9a8aff696c3a846ac5a51f762c1
http://otr.git.sourceforge.net/git/gitweb.cgi?p=otr/libotr%3Ba=commitdiff%3Bh=b17232f86f8e60d0d22caf9a2400494d3c77da58
https://bugzilla.redhat.com/show_bug.cgi?id=846377
libotr-base64-bo(77528)
https://exchange.xforce.ibmcloud.com/vulnerabilities/77528
openSUSE-SU-2012:1525
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00016.html
openSUSE-SU-2013:0155
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00019.html
CopyrightCopyright (C) 2012 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.