UBUNTU-CVE-2021-34813
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-34813
UBUNTU-CVE-2021-34813
Summary:
Details: Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.
References: https://ubuntu.com/security/CVE-2021-34813, https://gitlab.matrix.org/matrix-org/olm/-/commit/ccc0d122ee1b4d5e5ca4ec1432086be17d5f901b, https://gitlab.matrix.org/matrix-org/olm/-/releases/3.2.3, https://matrix.org/blog/2021/06/14/adventures-in-fuzzing-libolm, https://ubuntu.com/security/notices/USN-5194-1, https://www.cve.org/CVERecord?id=CVE-2021-34813
Affected packages
Package
Name: olm
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.1~esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
