CVE-2021-3345 REJECTED

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

EPSS 5.71% · 90.4th percentile

Risk Scores

EPSS Score
5.71%
90.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibgcrypt200, 1.6.3-2ubuntu1, 1.6.4-3
Ubuntu:Pro:14.04:LTSlibgcrypt110, 1.5.0-3ubuntu3, 1.5.3-2ubuntu1
Ubuntu:18.04:LTSlibgcrypt200, 1.7.8-2ubuntu1, 1.7.9-1
Ubuntu:20.04:LTSlibgcrypt200, 1.8.4-5ubuntu2, 1.8.5-3ubuntu1

Timeline

References

Open in Interactive Console →