9.8
CVSSv3

CVE-2021-34813

Published: 16/06/2021 Updated: 23/06/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Matrix libolm prior to 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

matrix olm

Vendor Advisories

Debian Bug report logs - #989997 olm: CVE-2021-34813 Package: src:olm; Maintainer for src:olm is Matrix Packaging Team <pkg-matrix-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 17 Jun 2021 13:48:01 UTC Severity: important Tags: security, upstream Found in vers ...
Matrix libolm before 323 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow Remote code execution might be possible for some nonstandard build configurations ...