Vulnerabilities > CVE-2021-34813 - Out-of-bounds Write vulnerability in Matrix OLM

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
matrix
CWE-787

Summary

Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations.

Vulnerable Configurations

Part Description Count
Application
Matrix
1

Common Weakness Enumeration (CWE)