CVE-2021-34813: Buffer Overflow
Published Jun 16, 2021
·Updated
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olmpkdecrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.
Affected Software
1 affected component
matrix olm<3.2.3
Remediation
Event History
Jun 16, 2021
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
Description
Frequently Asked Questions
1
What is CVE-2021-34813?
CVE-2021-34813 is a vulnerability in Matrix libolm before version 3.2.3 that allows a malicious Matrix homeserver to crash a client.
2
What is the severity of CVE-2021-34813?
The severity of CVE-2021-34813 is critical with a CVSS score of 9.8.
3
How does CVE-2021-34813 affect Matrix libolm?
CVE-2021-34813 affects Matrix libolm before version 3.2.3.
4
How can CVE-2021-34813 be exploited?
CVE-2021-34813 can potentially lead to remote code execution for some nonstandard build configurations.
5
How can I fix CVE-2021-34813?
To fix CVE-2021-34813, upgrade Matrix libolm to version 3.2.3 or later.