Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 17 submissions in the queue.

Submission Preview

Link to Story

OTR in Pidgin, ChatSecure, Adium etc compromised due to critical bug in libotr

Accepted submission by bitstream at 2016-03-12 12:25:47
Security

The C code library "libotr" that implements the Off-the-Record (OTR) protocol has a vulnerability CVE-2016-2851. The library is used in many secure instant messengers such as Pidgin, ChatSecure, Adium and Kopete. The library and the applications that use it could be exploited by attackers to crash an app running on your local machine using libotr or execute remote code [helpnetsecurity.com]. The bug is fixed in libotr v4.1.1 [cypherpunks.ca].


Original Submission