Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gc66-2jq6-66c6

Опубликовано: 22 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

EPSS

Процентиль: 35%
0.00145
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
nvd
больше 1 года назад

An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.3
debian
больше 1 года назад

An issue was discovered in Matrix libolm through 3.2.16. The AES imple ...

EPSS

Процентиль: 35%
0.00145
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-208