[Bug 789190] New: multiple buffer overflows in libotr
https://bugzilla.novell.com/show_bug.cgi?id=789190 https://bugzilla.novell.com/show_bug.cgi?id=789190#c0 Summary: multiple buffer overflows in libotr Classification: openSUSE Product: openSUSE 12.2 Version: Final Platform: All OS/Version: openSUSE 12.2 Status: NEW Severity: Normal Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: Andreas.Stieger@gmx.de QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux i686; rv:16.0) Gecko/20100101 Firefox/16.0 Versions 3.2.0 and earlier of libotr contain a small heap write overrun and a large heap read overrun http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3461 http://seclists.org/oss-sec/2012/q3/195 http://lists.cypherpunks.ca/pipermail/otr-dev/2012-July/001347.html devel package and openSUSE:Factory are on a later version. I am currently working on a compatibility package libotr2 with version 3.2.0 / 3.2.1 to fix irc-otr in openSUSE:Factory, ( #789175 ) which is how I found this. https://build.opensuse.org/request/show/140870 MRs following soon. Reproducible: Always Steps to Reproduce: 1. 2. 3. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=789190 https://bugzilla.novell.com/show_bug.cgi?id=789190#c1 --- Comment #1 from Andreas Stieger <Andreas.Stieger@gmx.de> 2012-11-11 22:00:44 UTC --- MR updating libotr to 3.2.1 for 12.1 and 12.2: https://build.opensuse.org/request/show/140887 SR for libotr 3.2.1 to devel:libraries:c_c++ as libotr2 to fix #789175 https://build.opensuse.org/request/show/140888 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=789190 https://bugzilla.novell.com/show_bug.cgi?id=789190#c2 --- Comment #2 from Nelson Marques <nmo.marques@gmail.com> 2012-11-11 23:59:25 UTC --- Hi, I submitted an update to 4.0.0 while I was doing a few random updates on GNOME:Apps; this one was motivated by a pidgeon plugin. It seems I can also take action on the libotr2 submission; I would ask one of the reviewers to take a look, I have no experience reviewing packages. +1 from my side Thanks for your submissions. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com