CVE-2021-34813

Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrix:olm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-06-16 18:15

Updated : 2024-11-21 06:11


NVD link : CVE-2021-34813

Mitre link : CVE-2021-34813

CVE.ORG link : CVE-2021-34813


JSON object : View

Products Affected

matrix

  • olm
CWE
CWE-787

Out-of-bounds Write