Ubuntu

“libotr” 3.2.0-2ubuntu1.1 source package in Ubuntu

Changelog

libotr (3.2.0-2ubuntu1.1) natty-security; urgency=low

  * SECURITY UPDATE: multiple heap-based buffer overflows (LP: #1034623)
    - src/b64.c, src/b64.h, src/proto.c, toolkit/parse.c:
      apply upstream git commits b17232f86f8e60d0d22caf9a2400494d3c77da58,
      6d4ca89cf1d3c9a8aff696c3a846ac5a51f762c1 and
      1902baee5d4b056850274ed0fa8c2409f1187435
    - CVE-2012-3461
 -- Felix Geyer <email address hidden>   Thu, 09 Aug 2012 15:30:03 +0200

Upload details

Uploaded by:
Felix Geyer on 2012-08-14
Sponsored by:
Steve Beattie
Uploaded to:
Natty
Original maintainer:
Ubuntu Developers
Component:
main
Architectures:
any
Section:
libs
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size MD5 Checksum
libotr_3.2.0.orig.tar.gz 420.2 KiB faba02e60f64e492838929be2272f839
libotr_3.2.0-2ubuntu1.1.diff.gz 5.0 KiB 921b658c643e835308124ffe9c1a49f8
libotr_3.2.0-2ubuntu1.1.dsc 1.8 KiB 4b8c3fad509a33e7041aafcdc62543a5

Binary packages built by this source

libotr2: Off-the-Record Messaging library

 Off-the-Record (OTR) Messaging Library and Toolkit
 .
 OTR allows you to have private conversations over IM by providing:
  - Encryption
    - No one else can read your instant messages.
  - Authentication
    - You are assured the correspondent is who you think it is.
  - Deniability
    - The messages you send do _not_ have digital signatures that are
      checkable by a third party. Anyone can forge messages after a
      conversation to make them look like they came from you. However,
      _during_ a conversation, your correspondent is assured the messages
      he sees are authentic and unmodified.
  - Perfect forward secrecy
    - If you lose control of your private keys, no previous conversation
      is compromised.

libotr2-bin: toolkit for Off-the-Record Messaging library

 Off-the-Record (OTR) Messaging Library toolkit
 .
 OTR allows you to have private conversations over IM by providing:
  - Encryption
    - No one else can read your instant messages.
  - Authentication
    - You are assured the correspondent is who you think it is.
  - Deniability
    - The messages you send do _not_ have digital signatures that are
      checkable by a third party. Anyone can forge messages after a
      conversation to make them look like they came from you. However,
      _during_ a conversation, your correspondent is assured the messages
      he sees are authentic and unmodified.
  - Perfect forward secrecy
    - If you lose control of your private keys, no previous conversation
      is compromised.
  .
  This package contains the program files for the OTR library.

libotr2-dev: Off-the-Record Messaging library development files

 Off-the-Record (OTR) Messaging Library
 .
 OTR allows you to have private conversations over IM by providing:
  - Encryption
    - No one else can read your instant messages.
  - Authentication
    - You are assured the correspondent is who you think it is.
  - Deniability
    - The messages you send do _not_ have digital signatures that are
      checkable by a third party. Anyone can forge messages after a
      conversation to make them look like they came from you. However,
      _during_ a conversation, your correspondent is assured the messages
      he sees are authentic and unmodified.
  - Perfect forward secrecy
    - If you lose control of your private keys, no previous conversation
      is compromised.
  .
  This package contains the header files and static libraries needed to
  develop applications using libotr.