id2969037security1100606370orig
Security

Patch closes security hole in messaging encryption tool

A software component for encrypting instant messaging clients has a flaw that could let attackers take over users' machines, but there's now a patch for the vulnerability.

The vulnerability is contained in libotr, short for OTR Messaging Library and Toolkit. The up-to-date version is now 4.1.1.

OTR stands for Off-the-Record Messaging. It's a a cryptographic protocol that scrambles messages sent through clients including Pidgin, ChatSecure and Adium.

The integer overflow flaw was found by Markus Vervier of the German company X41 D-Sec, which released an advisory

"This flaw could potentially be exploited by a remote attacker to cause a heap buffer overflow and subsequently for arbitrary code to be executed on the user's machine," X41 D-Sec wrote.

The company found the flaw during a manual code review. It can be exploited by sending a very large message from one client to another, which causes an integer overflow that leads to a heap overflow on 64-bit architectures, X41 D-Sec wrote.

The message sent must be more than 5.5 GB. That's huge, but OTR allows for sending fragmented messages that are then assembled by libotr, the company wrote.

"Sending such a message to a Pidgin client took only a few minutes on a fast network connection without visible signs of any attack to a user," it wrote.

The latest version of libotr can be downloaded here.

IDG Insider

PREVIOUS ARTICLE

« Windows 10 Mobile beta build 14283 has handy 'I'll be late' feature

NEXT ARTICLE

Justice Department slams Apple's 'corrosive' rhetoric in its latest court filing »
author_image
IDG News Service

The IDG News Service is the world's leading daily source of global IT news, commentary and editorial resources. The News Service distributes content to IDG's more than 300 IT publications in more than 60 countries.

  • Mail

Recommended for You

Trump hits partial pause on Huawei ban, but 5G concerns persist

Phil Muncaster reports on China and beyond

FinancialForce profits from PSA investment

Martin Veitch's inside track on today’s tech trends

Future-proofing the Middle East

Keri Allan looks at the latest trends and technologies

Poll

Do you think your smartphone is making you a workaholic?