Menu
Patch closes security hole in messaging encryption tool

Patch closes security hole in messaging encryption tool

The up-to-date version of the component, libotr, is 4.1.1

A software component for encrypting instant messaging clients has a flaw that could let attackers take over users' machines, but there's now a patch for the vulnerability.

The vulnerability is contained in libotr, short for OTR Messaging Library and Toolkit. The up-to-date version is now 4.1.1.

OTR stands for Off-the-Record Messaging. It's a a cryptographic protocol that scrambles messages sent through clients including Pidgin, ChatSecure and Adium.

The integer overflow flaw was found by Markus Vervier of the German company X41 D-Sec, which released an advisory

"This flaw could potentially be exploited by a remote attacker to cause a heap buffer overflow and subsequently for arbitrary code to be executed on the user's machine," X41 D-Sec wrote.

The company found the flaw during a manual code review. It can be exploited by sending a very large message from one client to another, which causes an integer overflow that leads to a heap overflow on 64-bit architectures, X41 D-Sec wrote.

The message sent must be more than 5.5 GB. That's huge, but OTR allows for sending fragmented messages that are then assembled by libotr, the company wrote.

"Sending such a message to a Pidgin client took only a few minutes on a fast network connection without visible signs of any attack to a user," it wrote.

The latest version of libotr can be downloaded here.


Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Featured

Slideshows

Sizing up the NZ security spectrum - Where's the channel sweet spot?

Sizing up the NZ security spectrum - Where's the channel sweet spot?

From new extortion schemes, outside threats and rising cyber attacks, the art of securing the enterprise has seldom been so complex or challenging. With distance no longer a viable defence, Kiwi businesses are fighting to stay ahead of the security curve. In total, 28 per cent of local businesses faced a cyber attack last year, with the number in New Zealand set to rise in 2017. Yet amidst the sensationalism, media headlines and ongoing high profile breaches, confusion floods the channel, as partners seek strategic methods to combat rising sophistication from attackers. In sizing up the security spectrum, this Reseller News roundtable - in association with F5 Networks, Kaspersky Lab, Tech Data, Sophos and SonicWall - assessed where the channel sweet spot is within the New Zealand channel. Photos by Maria Stefina.

Sizing up the NZ security spectrum - Where's the channel sweet spot?
Show Comments