CVE-2021-3345: Buffer Overflow
gcrymdblockwrite in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.9.1
Event History
Frequently Asked Questions
What is CVE-2021-3345?
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value.
What is the severity of CVE-2021-3345?
The severity of CVE-2021-3345 is high (7.8).
Which software versions are affected by CVE-2021-3345?
Libgcrypt version 1.9.0 and Oracle Communications Billing and Revenue Management version 12.0.0.3.0 are affected by CVE-2021-3345.
How can I fix CVE-2021-3345?
It is recommended to upgrade to Libgcrypt version 1.9.1 or later to fix CVE-2021-3345.
Where can I find more information about CVE-2021-3345?
You can find more information about CVE-2021-3345 at the following references: [link1], [link2], [link3].