ALT-BU-2016-2635-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2025-04-12
CVE-2016-2851
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00030.html
- http://seclists.org/fulldisclosure/2016/Mar/21
- http://www.debian.org/security/2016/dsa-3512
- http://www.securityfocus.com/archive/1/537745/100/0/threaded
- http://www.securityfocus.com/bid/84285
- http://www.ubuntu.com/usn/USN-2926-1
- https://lists.cypherpunks.ca/pipermail/otr-users/2016-March/002581.html
- https://security.gentoo.org/glsa/201701-10
- https://www.exploit-db.com/exploits/39550/
- https://www.x41-dsec.de/lab/advisories/x41-2016-001-libotr/
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00030.html
- http://seclists.org/fulldisclosure/2016/Mar/21
- http://www.debian.org/security/2016/dsa-3512
- http://www.securityfocus.com/archive/1/537745/100/0/threaded
- http://www.securityfocus.com/bid/84285
- http://www.ubuntu.com/usn/USN-2926-1
- https://lists.cypherpunks.ca/pipermail/otr-users/2016-March/002581.html
- https://security.gentoo.org/glsa/201701-10
- https://www.exploit-db.com/exploits/39550/
- https://www.x41-dsec.de/lab/advisories/x41-2016-001-libotr/
Package pidgin-otr updated to version 4.0.2-alt1 for branch sisyphus in task 161130.
Closed vulnerabilities
Modified: 2025-04-12
CVE-2015-8833
Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbitrary code via vectors related to the "Authenticate buddy" menu item.
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00095.html
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00109.html
- http://www.debian.org/security/2016/dsa-3528
- http://www.openwall.com/lists/oss-security/2016/03/09/13
- http://www.openwall.com/lists/oss-security/2016/03/09/8
- http://www.securityfocus.com/bid/84295
- https://blog.fuzzing-project.org/39-Heap-use-after-free-in-Pidgin-OTR-plugin-CVE-2015-8833.html
- https://bugs.otr.im/issues/128
- https://bugs.otr.im/issues/88
- https://bugs.otr.im/projects/pidgin-otr/repository/revisions/aaf551b9dd5cbba8c4abaa3d4dc7ead860efef94
- https://lists.cypherpunks.ca/pipermail/otr-users/2016-March/002582.html
- https://security.gentoo.org/glsa/201701-10
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00095.html
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00109.html
- http://www.debian.org/security/2016/dsa-3528
- http://www.openwall.com/lists/oss-security/2016/03/09/13
- http://www.openwall.com/lists/oss-security/2016/03/09/8
- http://www.securityfocus.com/bid/84295
- https://blog.fuzzing-project.org/39-Heap-use-after-free-in-Pidgin-OTR-plugin-CVE-2015-8833.html
- https://bugs.otr.im/issues/128
- https://bugs.otr.im/issues/88
- https://bugs.otr.im/projects/pidgin-otr/repository/revisions/aaf551b9dd5cbba8c4abaa3d4dc7ead860efef94
- https://lists.cypherpunks.ca/pipermail/otr-users/2016-March/002582.html
- https://security.gentoo.org/glsa/201701-10
Package firefox-esr updated to version 38.7.0-alt1 for branch sisyphus in task 161102.
Closed vulnerabilities
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
Closed bugs
lib.req doesn't give deps with the new ldd --list patch