Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3345

Опубликовано: 29 янв. 2021
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

A flaw was found in libgcrypt. A heap-based buffer overflow in the block buffer management code may lead to memory corruption before any verification is made or signature is validated. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

No Red Hat products are affected by this flaw, as the vulnerable version of libgcrypt (1.9.0) has not been shipped in any products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libgcryptNot affected
Red Hat Enterprise Linux 7libgcryptNot affected
Red Hat Enterprise Linux 8libgcryptNot affected
Red Hat Enterprise Linux 9libgcryptNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-191->CWE-122->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1923210libgcrypt: Heap buffer overflow in the block buffer management code

EPSS

Процентиль: 90%
0.05706
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

CVSS3: 7.8
nvd
около 5 лет назад

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

CVSS3: 7.8
debian
около 5 лет назад

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9. ...

CVSS3: 7.8
github
больше 3 лет назад

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt before 1.9.1 has a heap-based buffer overflow when the digest final function sets a large count value.

CVSS3: 7.8
fstec
около 5 лет назад

Уязвимость функции _gcry_md_block_write (cipher / hash-common.c) криптографической библиотеки Libgcrypt, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05706
Низкий

9.8 Critical

CVSS3