VDB

CVE-2021-34813

CVE-2021-34813 PUBLISHED

Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.

EPSS 4.46% · 89.3th percentile

Risk Scores

EPSS Score
4.46%
89.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSolm0, 3.1.3+dfsg-2, 3.1.3+dfsg-2build1

Timeline

  • Jun 16, 2021 CVE Published
  • Jun 17, 2021 EPSS Score
  • Aug 18, 2021 EPSS Score
  • Dec 17, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 15, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 17, 2022 EPSS Score
  • Aug 17, 2022 EPSS Score
  • Oct 16, 2022 EPSS Score
  • Dec 16, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›