Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 111645 - Security update for Libotr and gaim-otr (both to version 3.0.0)
Summary: Security update for Libotr and gaim-otr (both to version 3.0.0)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Net-im project
URL: http://www.cypherpunks.ca/otr/
Whiteboard:
Keywords:
: 111716 111718 112094 112095 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-11-05 17:43 UTC by Joshua Jackson (RETIRED)
Modified: 2005-11-13 22:12 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
gaim_otr diff update (gaim_otr.patch,331 bytes, text/plain)
2005-11-05 17:44 UTC, Joshua Jackson (RETIRED)
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Joshua Jackson (RETIRED) gentoo-dev 2005-11-05 17:43:10 UTC
Off the Record messaging protocol has a intrinsic binding flaw in the <=2.X. It
basically makes one person think they are talking to another.

The new version of otr is a complete rewrite, and also is a new protocol version
2 of the otr protocol. It will however have the ability to interact with the
older (<=2.X) version 1 protocol

Reproducible: Always
Steps to Reproduce:




Information about the security flaw can be found here.

http://lists.cypherpunks.ca/pipermail/otr-users/2005-July/000316.html
Comment 1 Joshua Jackson (RETIRED) gentoo-dev 2005-11-05 17:44:57 UTC
Created attachment 72253 [details]
gaim_otr diff update
Comment 2 Joshua Jackson (RETIRED) gentoo-dev 2005-11-05 17:58:52 UTC
I just tested the new version with gaim 1.5.0 (won't work on gaim-2.0 yet per
steev).

As a new warning about protcols. You'll see the following when you connect to
someone with the version 1 protocol.

 Unverified conversation with ${person} started.  Warning: using old protocol
version 1.
(17:55:50) Attempting to refresh the private conversation with ${person}...
(17:55:51) Successfully refreshed the unverified conversation with ${person}.
Warning: using old protocol version 1.
Comment 3 Jakub Moc (RETIRED) gentoo-dev 2005-11-06 13:45:22 UTC
*** Bug 111716 has been marked as a duplicate of this bug. ***
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2005-11-06 13:45:35 UTC
*** Bug 111718 has been marked as a duplicate of this bug. ***
Comment 5 Jakub Moc (RETIRED) gentoo-dev 2005-11-10 11:23:33 UTC
*** Bug 112094 has been marked as a duplicate of this bug. ***
Comment 6 Jakub Moc (RETIRED) gentoo-dev 2005-11-10 11:23:58 UTC
*** Bug 112095 has been marked as a duplicate of this bug. ***
Comment 7 Daniel Guido 2005-11-13 18:39:36 UTC
current version tarball for the gaim plugin is here:
http://www.cypherpunks.ca/otr/gaim-otr-3.0.0.tar.gz

link to main page: http://www.cypherpunks.ca/otr/

can someone make some ebuilds???
Comment 8 Don Seiler (RETIRED) gentoo-dev 2005-11-13 22:12:23 UTC
libotr and gaim-otr 3.0.0 committed to portage ~x86.

Sorry for delay in processing.