Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) otrl_base64_otr_decode function in src/b64.c; (2) otrl_proto_data_read_flags and (3) otrl_proto_accept_data functions in src/proto.c; and (4) decode function in toolkit/parse.c in libotr before 3.2.1 allocates a zero-length buffer when decoding a base64 string, which allows remote attackers to cause a denial of service (application crash) via a message with the value "?OTR:===.", which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Debian libotr 缓冲区错误漏洞
Vulnerability Description
Debian是Debian Project合作组织创建的以Linux或FreeBSD为内核的自由操作系统。 Debian libotr 3.2.1之前版本中存在多个基于堆的缓冲区溢出漏洞,这些漏洞源于应用程序对用户提供的数据未执行充分的边界值校验。攻击者可利用这些漏洞在用户运行的受影响应用程序上下文中执行任意代码,攻击失败将导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A