The (1) otrl_base64_otr_decode function in src/b64.c; (2) otrl_proto_data_read_flags and (3) otrl_proto_accept_data functions in src/proto.c; and (4) decode function in toolkit/parse.c in libotr before 3.2.1 allocates a zero-length buffer when decoding a base64 string, which allows remote attackers to cause a denial of service (application crash) via a message with the value "?OTR:===.", which triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libotr. | Aug 30, 2017 | Aug 20, 2012 |
| Debian | — | Upgrade libotr | Jul 30, 2024 | Aug 20, 2012 |
| Freebsd | — | Upgrade libotr | Dec 10, 2025 | Aug 18, 2012 |
| Gentoo Linux | — | Upgrade net-libs/libotr. | Oct 30, 2017 | Aug 20, 2012 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2Upgrade system/library to version 0.5.11-0.175.0.12.0.3.1 on Solaris 11.0 | May 29, 2017 | Aug 20, 2012 |
| Suse | — | Upgrade libotr2Upgrade libotr-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libotr2 | Nov 8, 2024 | Aug 20, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub