CVE-2021-3345

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnupg:libgcrypt:1.9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:21

Type Values Removed Values Added
References () https://bugs.gentoo.org/show_bug.cgi?id=767814 - Issue Tracking, Vendor Advisory () https://bugs.gentoo.org/show_bug.cgi?id=767814 - Issue Tracking, Vendor Advisory
References () https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=512c0c75276949f13b6373b5c04f7065af750b08 - () https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=512c0c75276949f13b6373b5c04f7065af750b08 -
References () https://gnupg.org - Vendor Advisory () https://gnupg.org - Vendor Advisory
References () https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.html - Mailing List, Vendor Advisory () https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.html - Mailing List, Vendor Advisory
References () https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.html - Mailing List, Patch, Vendor Advisory () https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.html - Mailing List, Patch, Vendor Advisory
References () https://www.oracle.com//security-alerts/cpujul2021.html - Third Party Advisory () https://www.oracle.com//security-alerts/cpujul2021.html - Third Party Advisory

07 Nov 2023, 03:37

Type Values Removed Values Added
References
  • {'url': 'https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=512c0c75276949f13b6373b5c04f7065af750b08', 'name': 'https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=512c0c75276949f13b6373b5c04f7065af750b08', 'tags': ['Mailing List', 'Patch', 'Third Party Advisory'], 'refsource': 'MISC'}
  • () https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=512c0c75276949f13b6373b5c04f7065af750b08 -

Information

Published : 2021-01-29 15:15

Updated : 2024-11-21 06:21


NVD link : CVE-2021-3345

Mitre link : CVE-2021-3345

CVE.ORG link : CVE-2021-3345


JSON object : View

Products Affected

oracle

  • communications_billing_and_revenue_management

gnupg

  • libgcrypt
CWE
CWE-787

Out-of-bounds Write