CVE-2012-236 - Format string security flaw in pidgin-otr

An instant messenger which can connect to AIM, GTalk, Jabber, ICQ, and more.
Post Reply
famato
Harmless
Posts: 3
Joined: Mon Jun 04, 2012 3:21 pm

CVE-2012-236 - Format string security flaw in pidgin-otr

Post by famato »

Hi there,
I would like to know if the following vulnerability is patched in the last versions of Adium:
http://lists.cypherpunks.ca/pipermail/o ... 00026.html

"
Off-the-Record Messaging (OTR) Security Advisory 2012-01

Format string security flaw in pidgin-otr

Versions 3.2.0 and earlier of the pidgin-otr plugin contain a format
string security flaw. This flaw could potentially be exploited by
a remote attacker to cause arbitrary code to be executed on the user's
machine.

The flaw is in pidgin-otr, not in libotr. Other applications which use
libotr are not affected.

CVE-2012-2369 has been assigned to this issue.
"

I couldnt find any information about it.
Best
User avatar
Robby
Cocoaforge Admin
Posts: 2610
Joined: Mon May 01, 2006 3:00 am

Re: CVE-2012-236 - Format string security flaw in pidgin-otr

Post by Robby »

The flaw is in pidgin-otr, not in libotr. Other applications that use libotr are not affected.
=-)

http://www.cypherpunks.ca/otr/
famato
Harmless
Posts: 3
Joined: Mon Jun 04, 2012 3:21 pm

Re: CVE-2012-236 - Format string security flaw in pidgin-otr

Post by famato »

I'm asking because i didnt know. I think adium is based on pidgin. So are you sure?
Thanks
User avatar
Robby
Cocoaforge Admin
Posts: 2610
Joined: Mon May 01, 2006 3:00 am

Re: CVE-2012-236 - Format string security flaw in pidgin-otr

Post by Robby »

Both Adium and Pidgin are based on libpurple.

Adium uses the libotr library for its OTR support and no further plugin is required whereas Pidgin doesn't come with OTR support out of the box. This particular security issue was with the plugin for Pidgin.
famato
Harmless
Posts: 3
Joined: Mon Jun 04, 2012 3:21 pm

Re: CVE-2012-236 - Format string security flaw in pidgin-otr

Post by famato »

Thanks really clear!
Best
Post Reply