Germany’s X41 D-SEC GmbH has found that the libotr library can be remotely exploited. The flaw could potentially be exploited by a remote attacker to cause a heap buffer overflow and subsequently for arbitrary code to be executed on the users machine. The vulnerability is triggered if a value of 0xFFFFFFFF (MAX_UINT) is read from the message buffer. A particular 5.5 GB long message sent to the llibotr can trigger the vulnerability. Users should upgrade to version 4.1.1 as soon as possible.”]
Source: https://securityintelligence.com/news/research-finds-libotr-can-be-exploited-remotely/