CVE-2016-2851
CRITICALDebian Linux < 4.1.0 - Memory Corruption
Title source: ruleDescription
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.
Exploits (1)
exploitdb
WORKING POC
by X41 D-Sec GmbH · pythondosmultiple
https://www.exploit-db.com/exploits/39550
References (11)
Scores
CVSS v3
9.8
EPSS
0.2306
EPSS Percentile
95.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (5)
cypherpunks/libotr
< 4.1.0
debian/debian_linux
7.0
debian/debian_linux
8.0
opensuse/leap
42.1
opensuse/opensuse
13.2
Published
Apr 07, 2016
Tracked Since
Feb 18, 2026