Описание
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 0.6.3-4.2ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [4.0.0-2.2ubuntu1.1]] |
| precise | released | 3.2.0-4ubuntu0.3 |
| trusty | released | 4.0.0-2.2ubuntu1.1 |
| trusty/esm | DNE | trusty was released [4.0.0-2.2ubuntu1.1] |
| upstream | released | 4.1.1 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| wily | released | 4.1.0-2ubuntu0.1 |
Показывать по
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms ...
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3