The C code library "libotr" that implements the Off-the-Record (OTR) protocol has a vulnerability CVE-2016-2851. The library is used in many secure instant messengers such as Pidgin, ChatSecure, Adium and Kopete. The library and the applications that use it could be exploited by attackers to crash an app running on your local machine using libotr or execute remote code [helpnetsecurity.com]. The bug is fixed in libotr v4.1.1 [cypherpunks.ca].